Common Vendor Oversight Inspection Findings

A practical guide to recurring inspection findings involving outsourced pharmacovigilance activities and vendor governance.

Audio Lesson 13 min

Common Vendor Oversight Inspection Findings

Introduction

Vendor oversight is one of the most frequently scrutinised areas during pharmacovigilance inspections.

This is not because regulators oppose outsourcing.

Modern pharmacovigilance systems depend heavily upon external providers.

Instead, inspectors focus on a different question:

Does the Marketing Authorisation Holder maintain effective control of outsourced activities?

Many inspection findings arise when organisations can demonstrate outsourcing but struggle to demonstrate oversight.

The purpose of this article is not to create anxiety.

The purpose is to identify recurring weaknesses and explain the governance failures that often sit behind them.

Understanding Inspection Expectations

Inspectors generally recognise that:

The expectation is not direct operational control.

The expectation is effective oversight.

Inspectors typically evaluate:

When weaknesses appear in these areas, findings often follow.

Regulatory context

Common Findings (Summary)

  1. Incomplete vendor inventories
  2. Weak vendor risk assessment
  3. Unclear responsibilities
  4. Weak or outdated SDEAs
  5. Lack of evidence of oversight
  6. Ineffective KPI monitoring
  7. Weak audit programmes
  8. CAPA failures
  9. Limited QPPV visibility
  10. Failure to align documentation
  11. Over-reliance on vendors
  12. Weak change control

Many of these findings are symptoms of the same governance gaps: poor documentation of oversight, lack of risk-based prioritisation, and weak evidence trails.

For detailed descriptions and prevention approaches, see the sections below and the inspection‑ready appendix.

Governance and Roles

Effective vendor oversight requires clear governance. Typical responsibilities include:

Governance elements that inspectors will review include documented role descriptions, escalation pathways, documented meeting cadence, and evidence of senior level involvement (minutes, actions, signatures).

What Inspectors Are Really Assessing

Although findings may appear diverse, most relate to a small number of governance questions.

Most findings ultimately reflect weaknesses in one or more of these areas.

Characteristics of Inspection-Ready Vendor Oversight

Organisations that perform well during inspections commonly demonstrate:

Key Takeaways

References

  1. EMA Good Pharmacovigilance Practices (GVP) Module I – Pharmacovigilance Systems and Their Quality Systems.
  2. EMA Good Pharmacovigilance Practices (GVP) Module II – Pharmacovigilance System Master File.
  3. EMA Good Pharmacovigilance Practices (GVP) Module III – Pharmacovigilance Inspections.
  4. Regulation (EC) No 726/2004.
  5. Directive 2001/83/EC.
  6. Commission Implementing Regulation (EU) No 520/2012.
  7. ICH Q9 Quality Risk Management.
  8. PIC/S Guidance on Pharmacovigilance Inspections.

Inspection‑Ready Appendix: Checklists and Sample Templates

This appendix provides inspection-ready checklists and sample templates to implement and demonstrate vendor oversight in an inspectable format. Each template includes practical implementation details, regulatory context and notes on what inspectors are likely to verify. Use these templates as baseline artefacts: adapt fields and thresholds to your organisation’s risk profile and regulatory footprint.

How to use this appendix

Inspection relevance

A. Vendor Inventory — Checklist and Template

Purpose: Provide a single source of truth for all PV‑related vendors and services. This is a primary inspection document and should be cross-referenced to the PSMF.

Inventory maintenance guidance

Vendor Inventory Template (tabular – recommended as spreadsheet)

Field Description / Instructions Example
Vendor ID Unique identifier VEND‑01234
Vendor name Legal entity and trading name ABC Safety Services Ltd
Country of registration Jurisdiction UK
Service category High level (e.g., ICSRs, medical information, signal detection) ICSR processing
Detailed services Specific activities performed Case intake, triage, coding, submission to EudraVigilance
Products/MAHs covered Product names and MAH codes Product A (MAH‑001), Product B (MAH‑002)
Contract/SOW reference Contract number and version CTR‑2024‑PV‑001 v2
SDEA in place? Yes/No + version/date Yes — SDEA v1.3 dated 2025‑03‑12
Criticality / Risk rating High/Medium/Low with rationale High — handles all serious SUSARs
Start date / End date Contract effective and expiry date 2023‑06‑01 / 2027‑05‑31
Contact person Vendor operational contact Dr. Jane Smith, Head of PV
Onsite access Yes/No No
Last audit date Date and type (on‑site/remote) 2025‑01‑15 (remote)
Next planned audit Date 2026‑01‑15
KPI adherence Current status (Green/Amber/Red) Amber
CAPA open? Yes/No + CAPA ID Yes — CAPA‑2025‑045
Notes / Change control ref Link to change control / PSMF section CHG‑2025‑12

Inspection relevance: Inspectors will cross-check inventory entries against SDEAs, contracts, PSMF and audit reports. Missing vendors or inconsistencies are common findings.

Practical implementation tips

B. SDEA Clauses — Essential Elements and Sample Clauses

Regulatory context: SDEAs (or equivalent safety data exchange mechanisms) are expected by EMA and other authorities to formalise safety reporting obligations between MAHs and service providers (ICH and GVP guidance). An SDEA must reflect the actual operating processes.

Principles for SDEAs

Essential clauses (checklist)

Sample SDEA text (excerpts)

Inspection relevance: Inspectors will read the SDEA and compare it to observed operational practice, including timelines in system records, case processing logs and audit reports. Discrepancies between the SDEA and practice are frequent inspection findings.

Practical drafting and maintenance

C. KPI Template and Thresholds — Sample Matrix

Purpose: KPIs must be measurable, relevant to risk and tied to escalation and CAPA mechanisms. Inspectors will verify that KPI breaches lead to documented actions.

KPI design principles

Sample KPI matrix

KPI ID KPI name Objective Calculation / Data source Frequency Thresholds (Green/Amber/Red) Escalation action Owner
KPI‑001 ICSR intake timeliness Ensure prompt capture of reports % ICSRs entered into system within 24h of receipt (source: case intake logs) Weekly / Monthly Green ≥ 95% / Amber 90–94.9% / Red <90% Amber: Vendor remediation plan within 5 working days. Red: Formal governance meeting within 3 working days; QA audit trigger Vendor Manager
KPI‑002 Serious case submission to MAH Ensure vendor forwards serious ICSRs promptly % serious ICSRs forwarded to MAH within agreed timeframe (72h) Weekly Green ≥ 100% / Amber 95–99.9% / Red <95% Amber: CAPA proposal within 7 days. Red: Immediate CAPA and interim monitoring Vendor Manager
KPI‑003 Coding quality Ensure accurate MedDRA coding % of random sample coding concordant with MAH adjudication (sample size monthly) Monthly Green ≥ 98% / Amber 95–97.9% / Red <95% Amber: Targeted retraining. Red: Root cause analysis and audit Quality
KPI‑004 Query closure time Reduce open queries backlog Median time to close clinical queries (days) Monthly Green ≤ 7 / Amber 8–14 / Red >14 Amber: Bi‑weekly monitoring report. Red: Governance escalation Vendor Manager
KPI‑005 Aggregate report delivery Timely submission of PSUR/DSUR components % on time delivery of vendor deliverables for aggregate reports Quarterly Green 100% / Amber 95–99.9% / Red <95% Amber: Corrective plan. Red: Contract review and potential audit PV Lead

Notes on thresholds

Practical implementation

D. Audit Schedule Template and Example Audit Checklist

Regulatory context: Audits are a primary mechanism to verify vendor activities. EMA GVP and PIC/S emphasise independent verification of outsourced critical functions.

Audit programme design principles

Audit schedule template (sample)

Vendor ID Vendor name Service category Risk rating Last audit date / type Next audit date / type Rationale for frequency
VEND‑01234 ABC Safety Services Ltd ICSR processing High 2025‑01‑15 (remote) 2026‑01‑15 (on‑site) High criticality and history of KPI excursions
VEND‑04567 MedInfo Solutions Medical information Medium 2024‑09‑10 (on‑site) 2026‑09‑10 (remote) Medium risk; stable performance

Audit checklist (sample items)

Audit report and follow-up

Inspection relevance: Inspectors will examine audit reports, CAPA registers and evidence of effectiveness checks. They will verify whether audit scope corresponds to current risk and whether findings led to sustained improvement.

E. CAPA Register and Verification Evidence Template

Purpose: CAPAs must be actionable, timebound and include documented evidence of implementation and verification of effectiveness. Recurrent findings often result from weak CAPA design or lack of verification.

CAPA register fields (tabular)

CAPA ID Date opened Origin (audit/KPI/event) Description of issue Root cause summary Corrective action(s) Preventive action(s) Owner Target date Status Evidence location Verification method Date verified
CAPA‑2025‑045 2025‑02‑10 Audit VEND‑01234 Delayed forwarding of serious ICSRs Lack of KPI monitoring and no escalation matrix Implement automated forwarding within 24h; retrain staff; update SDEA Monthly review of forwarding logs and KPI refinement PV Vendor Manager 2025‑03‑31 Closed CAPA folder / eTMF Trend analysis of 3 months; sample recheck of cases 2025‑06‑15

Verification evidence examples

Verification method guidance

Inspection relevance: Inspectors will request CAPA records and verification evidence. Vague statements of “CAPA implemented” without supporting evidence are frequent deficiencies.

F. Example Governance Meeting Pack — Minimum Contents

For each vendor governance meeting (periodic), maintain a meeting pack that is retained and searchable.

Minimum contents

Inspection relevance: Inspectors commonly request meeting minutes to confirm governance activity. Minutes without clear decisions, owners and deadlines are inadequate.

G. Implementation Roadmap — Practical Steps to Create an Inspection‑Ready Package

  1. Assign ownership and accountability
  2. Nominate a named PV Vendor Manager and confirm QPPV oversight responsibilities.
  3. Document responsibilities in the vendor governance SOP.
  4. Build and stabilise the vendor inventory
  5. Populate the template, link contracts and SDEAs, and reconcile with procurement and PSMF.
  6. Review SDEAs and contracts
  7. Verify clauses align with real operations; amend SDEAs where discrepancies exist; maintain version history.
  8. Establish KPIs and thresholds
  9. Define KPIs, data sources, owners and thresholds; implement automated data extraction where feasible.
  10. Design audit programme
  11. Risk‑based audit frequency, scopes and resource allocation; schedule audits and track completion.
  12. Implement CAPA process
  13. CAPA register template; require evidence of implementation and independent effectiveness verification.
  14. Embed meeting cadence and documentation
  15. Regular vendor governance meetings; standardised meeting packs and minutes.
  16. Integrate change control
  17. Ensure change triggers update inventory, risk assessment, SDEA and audit schedule.
  18. Test inspection readiness
  19. Perform internal mock inspection: request documents as inspector would and validate retrieval time and completeness.
  20. Maintain continuous improvement
    • Review processes after audits and inspections to address systemic gaps.

Timing and resource considerations

Ensure that each artefact is cross‑referenced and easily accessible for inspection:

Inspection relevance: Inspectors will follow a document trail across artefacts. Lack of logical traceability commonly leads to findings.

I. Sample Evidence Checklist for Inspection Box

Prepare an inspection pack (electronic or physical) with the following items per critical vendor:

Presentation guidance

Inspection relevance: An organised inspection pack significantly reduces the risk of findings associated with missing evidence and demonstrates governance maturity.


This appendix is designed to be practical and inspection‑ready: populate the templates with operational data, maintain version control, and integrate the artefacts into your quality management system. These materials enable you to demonstrate effective oversight that is traceable, risk‑based and verifiable — the core elements inspectors expect when assessing outsourced pharmacovigilance activities.

Last reviewed: 2026-06-11