Common Vendor Oversight Inspection Findings
- Common Vendor Oversight Inspection Findings
- Inspection‑Ready Appendix: Checklists and Sample Templates
- A. Vendor Inventory — Checklist and Template
- B. SDEA Clauses — Essential Elements and Sample Clauses
- C. KPI Template and Thresholds — Sample Matrix
- D. Audit Schedule Template and Example Audit Checklist
- E. CAPA Register and Verification Evidence Template
- F. Example Governance Meeting Pack — Minimum Contents
- G. Implementation Roadmap — Practical Steps to Create an Inspection‑Ready Package
- H. Cross‑Referencing and Documentation Links
- I. Sample Evidence Checklist for Inspection Box
Introduction
Vendor oversight is one of the most frequently scrutinised areas during pharmacovigilance inspections.
This is not because regulators oppose outsourcing.
Modern pharmacovigilance systems depend heavily upon external providers.
Instead, inspectors focus on a different question:
Does the Marketing Authorisation Holder maintain effective control of outsourced activities?
Many inspection findings arise when organisations can demonstrate outsourcing but struggle to demonstrate oversight.
The purpose of this article is not to create anxiety.
The purpose is to identify recurring weaknesses and explain the governance failures that often sit behind them.
Understanding Inspection Expectations
Inspectors generally recognise that:
- Activities may be outsourced.
- Vendors may perform critical functions.
- Global operating models are common.
The expectation is not direct operational control.
The expectation is effective oversight.
Inspectors typically evaluate:
- Accountability
- Governance
- Risk management
- Visibility
- Escalation
- Continuous improvement
When weaknesses appear in these areas, findings often follow.
Regulatory context
- EMA GVP Module I (Pharmacovigilance Systems and Their Quality Systems) and Module II (PSMF) emphasise that MAHs are accountable for the pharmacovigilance system even when activities are outsourced.
- ICH Q9 (Quality Risk Management) underpins expectations for risk-proportionate oversight.
- PIC/S inspection guidance and national authority inspection manuals reiterate the need for documented, demonstrable oversight activities.
Common Findings (Summary)
- Incomplete vendor inventories
- Weak vendor risk assessment
- Unclear responsibilities
- Weak or outdated SDEAs
- Lack of evidence of oversight
- Ineffective KPI monitoring
- Weak audit programmes
- CAPA failures
- Limited QPPV visibility
- Failure to align documentation
- Over-reliance on vendors
- Weak change control
Many of these findings are symptoms of the same governance gaps: poor documentation of oversight, lack of risk-based prioritisation, and weak evidence trails.
For detailed descriptions and prevention approaches, see the sections below and the inspection‑ready appendix.
Governance and Roles
Effective vendor oversight requires clear governance. Typical responsibilities include:
- QPPV / Senior PV leader: retains ultimate accountability for pharmacovigilance activities and must have visibility of critical outsourced functions.
- PV Vendor Manager / Oversight Lead: operational owner of vendor relationships, inventory maintenance, KPI review and escalation.
- Head of Quality / QA: responsible for audit programmes, CAPA oversight and integration with the quality system.
- Procurement / Legal: contract execution, SDEA negotiation, change control triggers.
- System Owners / IT: ensure technical access, data integrity, and system-level validations.
- Business Product Owners: ensure contractual alignment to product profiles, safety reporting obligations and country-specific requirements.
Governance elements that inspectors will review include documented role descriptions, escalation pathways, documented meeting cadence, and evidence of senior level involvement (minutes, actions, signatures).
What Inspectors Are Really Assessing
Although findings may appear diverse, most relate to a small number of governance questions.
- Visibility: Does the organisation understand its vendor landscape?
- Accountability: Are responsibilities clear and assigned to named people?
- Control: Can oversight effectiveness be demonstrated with records?
- Risk Management: Is oversight proportional to risk and monitored over time?
- Continuous Improvement: Are problems identified, CAPAs implemented and effectiveness verified?
Most findings ultimately reflect weaknesses in one or more of these areas.
Characteristics of Inspection-Ready Vendor Oversight
Organisations that perform well during inspections commonly demonstrate:
- Accurate vendor inventories, regularly reconciled to the PSMF
- Current, activity-reflective SDEAs
- Risk-proportionate oversight with documented rationale
- Active governance with documented meeting minutes and decisions
- Effective, risk-based audit programmes with documented follow-up and effectiveness checks
- Measurable KPIs with thresholds, trend review and escalation triggers
- CAPA processes that include root cause analysis and verifiable effectiveness evidence
- QPPV visibility into critical vendors and major incidents
- Integrated change control linking vendor changes to contract/SDEA updates and risk reassessment
Key Takeaways
- Most vendor oversight findings reflect governance weaknesses rather than operational failures.
- Accurate inventories, risk-based oversight and maintained SDEAs are foundational.
- KPIs, audits and CAPAs must be actionable and demonstrable.
- QPPV visibility and documentation alignment (PSMF, SOPs, contracts) are essential.
- Treat vendor oversight as a continuous governance activity, not an episodic inspection preparation exercise.
References
- EMA Good Pharmacovigilance Practices (GVP) Module I – Pharmacovigilance Systems and Their Quality Systems.
- EMA Good Pharmacovigilance Practices (GVP) Module II – Pharmacovigilance System Master File.
- EMA Good Pharmacovigilance Practices (GVP) Module III – Pharmacovigilance Inspections.
- Regulation (EC) No 726/2004.
- Directive 2001/83/EC.
- Commission Implementing Regulation (EU) No 520/2012.
- ICH Q9 Quality Risk Management.
- PIC/S Guidance on Pharmacovigilance Inspections.
Inspection‑Ready Appendix: Checklists and Sample Templates
This appendix provides inspection-ready checklists and sample templates to implement and demonstrate vendor oversight in an inspectable format. Each template includes practical implementation details, regulatory context and notes on what inspectors are likely to verify. Use these templates as baseline artefacts: adapt fields and thresholds to your organisation’s risk profile and regulatory footprint.
How to use this appendix
- Populate templates with live data and store in the controlled quality system (eTMF / QMS / PSMF repositories).
- Assign ownership (named person, role) and record date/version.
- Ensure templates are traceable to contracts, SOPs, PSMF sections and audit reports.
- Maintain an audit trail of updates (change control) and reconcile with the vendor inventory at least quarterly (more frequently for critical vendors).
Inspection relevance
- Inspectors will expect to see a complete, current vendor inventory; signed SDEAs reflecting operations; an audit schedule with executed audits; CAPA records with evidence of implementation and effectiveness checks; and KPI reporting with defined thresholds and documented escalation where thresholds were breached.
A. Vendor Inventory — Checklist and Template
Purpose: Provide a single source of truth for all PV‑related vendors and services. This is a primary inspection document and should be cross-referenced to the PSMF.
Inventory maintenance guidance
- Owner: PV Vendor Manager (named) with QA oversight.
- Update frequency: Quarterly for all vendors; immediate update for changes impacting critical services.
- Reconciliation: Quarterly reconciliation between procurement, contract repository, and PSMF.
- Audit trail: Each change must be logged (what changed, why, who approved, reference to change control).
Vendor Inventory Template (tabular – recommended as spreadsheet)
| Field | Description / Instructions | Example |
|---|---|---|
| Vendor ID | Unique identifier | VEND‑01234 |
| Vendor name | Legal entity and trading name | ABC Safety Services Ltd |
| Country of registration | Jurisdiction | UK |
| Service category | High level (e.g., ICSRs, medical information, signal detection) | ICSR processing |
| Detailed services | Specific activities performed | Case intake, triage, coding, submission to EudraVigilance |
| Products/MAHs covered | Product names and MAH codes | Product A (MAH‑001), Product B (MAH‑002) |
| Contract/SOW reference | Contract number and version | CTR‑2024‑PV‑001 v2 |
| SDEA in place? | Yes/No + version/date | Yes — SDEA v1.3 dated 2025‑03‑12 |
| Criticality / Risk rating | High/Medium/Low with rationale | High — handles all serious SUSARs |
| Start date / End date | Contract effective and expiry date | 2023‑06‑01 / 2027‑05‑31 |
| Contact person | Vendor operational contact | Dr. Jane Smith, Head of PV |
| Onsite access | Yes/No | No |
| Last audit date | Date and type (on‑site/remote) | 2025‑01‑15 (remote) |
| Next planned audit | Date | 2026‑01‑15 |
| KPI adherence | Current status (Green/Amber/Red) | Amber |
| CAPA open? | Yes/No + CAPA ID | Yes — CAPA‑2025‑045 |
| Notes / Change control ref | Link to change control / PSMF section | CHG‑2025‑12 |
Inspection relevance: Inspectors will cross-check inventory entries against SDEAs, contracts, PSMF and audit reports. Missing vendors or inconsistencies are common findings.
Practical implementation tips
- Use a controlled spreadsheet or database with role‑based access.
- Include hyperlinks to contract documents and SDEAs.
- Implement automated reminders for review and audit scheduling.
- Include a “last reconciled” timestamp and signature field for the reviewer.
B. SDEA Clauses — Essential Elements and Sample Clauses
Regulatory context: SDEAs (or equivalent safety data exchange mechanisms) are expected by EMA and other authorities to formalise safety reporting obligations between MAHs and service providers (ICH and GVP guidance). An SDEA must reflect the actual operating processes.
Principles for SDEAs
- Must align to actual operational responsibility, not only contractual wording.
- Include timelines and formats for expedited reporting and aggregate reporting.
- Include data privacy and data transfer provisions that comply with applicable laws.
- Define access to source data and audit rights.
- Include change control and amendment procedures.
Essential clauses (checklist)
- Parties and scope (explicit activities)
- Definitions (ICSR, SUSAR, SAE, aggregate reports)
- Reporting obligations (who reports what, to whom, timeframe)
- Timelines and formats (e.g., 15 calendar days for serious unexpected ADRs)
- Source data access / documentation retention
- Audit and inspection rights
- Subcontracting and flow‑down obligations
- Data protection and confidentiality
- Roles for signal detection and safety surveillance (if applicable)
- Change management and amendment process
- Termination and data return/transfer on exit
- CAPA and remediation obligations
- Applicable law and dispute resolution
Sample SDEA text (excerpts)
-
Scope: "This SDEA governs the exchange of individual case safety reports (ICSRs), expedited reports, periodic aggregate safety reports and safety‑related information between [MAH] and [Vendor] for the products listed in Appendix A. The Vendor shall perform ICSR intake, processing, coding, and submission as specified in the Contract and in this SDEA."
-
Reporting obligations: "Vendor shall notify MAH of all serious adverse events within 24 hours of case intake. Vendor shall submit completed and Quality‑checked ICSRs to MAH within 72 hours. For SUSARs originating in clinical trials, Vendor shall provide initial notification to MAH within 24 hours and a complete narrative and transmission in E2B format within 7 calendar days."
-
Timelines: "All expedited reports shall be transmitted in ICH E2B(R3) formatted XML, and templates for non‑XML transmissions are defined in Appendix B. MAH remains responsible for final submissions to regulatory authorities; Vendor submissions to regulators require explicit prior authorisation."
-
Audit rights: "MAH or its authorised representative shall have the right to audit Vendor operations related to safety at reasonable intervals, with the right to review records and systems, subject to reasonable notice and confidentiality obligations."
Inspection relevance: Inspectors will read the SDEA and compare it to observed operational practice, including timelines in system records, case processing logs and audit reports. Discrepancies between the SDEA and practice are frequent inspection findings.
Practical drafting and maintenance
- Keep an SDEA version control log (date, change reason, approver).
- Trigger SDEA review on any change in service scope, regulatory reporting processes, country coverage, or system migrations.
- Store signed SDEAs in contract repository and link to inventory.
C. KPI Template and Thresholds — Sample Matrix
Purpose: KPIs must be measurable, relevant to risk and tied to escalation and CAPA mechanisms. Inspectors will verify that KPI breaches lead to documented actions.
KPI design principles
- Define the objective of each KPI (completeness, timeliness, quality).
- Include unit of measurement, data source, calculation method, frequency of reporting.
- Set thresholds and specify escalation actions for each threshold.
- Define owner for each KPI and evidence required upon breach.
Sample KPI matrix
| KPI ID | KPI name | Objective | Calculation / Data source | Frequency | Thresholds (Green/Amber/Red) | Escalation action | Owner |
|---|---|---|---|---|---|---|---|
| KPI‑001 | ICSR intake timeliness | Ensure prompt capture of reports | % ICSRs entered into system within 24h of receipt (source: case intake logs) | Weekly / Monthly | Green ≥ 95% / Amber 90–94.9% / Red <90% | Amber: Vendor remediation plan within 5 working days. Red: Formal governance meeting within 3 working days; QA audit trigger | Vendor Manager |
| KPI‑002 | Serious case submission to MAH | Ensure vendor forwards serious ICSRs promptly | % serious ICSRs forwarded to MAH within agreed timeframe (72h) | Weekly | Green ≥ 100% / Amber 95–99.9% / Red <95% | Amber: CAPA proposal within 7 days. Red: Immediate CAPA and interim monitoring | Vendor Manager |
| KPI‑003 | Coding quality | Ensure accurate MedDRA coding | % of random sample coding concordant with MAH adjudication (sample size monthly) | Monthly | Green ≥ 98% / Amber 95–97.9% / Red <95% | Amber: Targeted retraining. Red: Root cause analysis and audit | Quality |
| KPI‑004 | Query closure time | Reduce open queries backlog | Median time to close clinical queries (days) | Monthly | Green ≤ 7 / Amber 8–14 / Red >14 | Amber: Bi‑weekly monitoring report. Red: Governance escalation | Vendor Manager |
| KPI‑005 | Aggregate report delivery | Timely submission of PSUR/DSUR components | % on time delivery of vendor deliverables for aggregate reports | Quarterly | Green 100% / Amber 95–99.9% / Red <95% | Amber: Corrective plan. Red: Contract review and potential audit | PV Lead |
Notes on thresholds
- Thresholds must be justified in the KPI procedure (risk basis, historical performance, regulatory importance).
- Use tighter thresholds for critical processes (e.g., expedited reporting) and looser thresholds for lower‑risk support activities.
- Inspectors will request trend data over time and evidence of actions taken when thresholds were breached.
Practical implementation
- Automate KPI extraction from vendor systems where possible.
- Retain raw data and calculations for audit trail.
- Include KPI review on standard governance meeting agendas and capture minutes and decisions.
D. Audit Schedule Template and Example Audit Checklist
Regulatory context: Audits are a primary mechanism to verify vendor activities. EMA GVP and PIC/S emphasise independent verification of outsourced critical functions.
Audit programme design principles
- Risk‑based selection of vendors and audit frequency.
- Clear audit scope aligned to criticality and recent performance (KPIs, previous findings).
- Defined audit types: full on‑site, remote, focused (e.g., process review), follow‑up.
- Defined roles: lead auditor, sponsor (MAH), vendor contact.
- Documented closure and effectiveness verification process.
Audit schedule template (sample)
| Vendor ID | Vendor name | Service category | Risk rating | Last audit date / type | Next audit date / type | Rationale for frequency |
|---|---|---|---|---|---|---|
| VEND‑01234 | ABC Safety Services Ltd | ICSR processing | High | 2025‑01‑15 (remote) | 2026‑01‑15 (on‑site) | High criticality and history of KPI excursions |
| VEND‑04567 | MedInfo Solutions | Medical information | Medium | 2024‑09‑10 (on‑site) | 2026‑09‑10 (remote) | Medium risk; stable performance |
Audit checklist (sample items)
- Governance and contracts
- Is there a current contract and SDEA? Are versions aligned with inventory?
- Is there an organisational chart and named staffing for PV roles?
- Case processing
- Are intake logs complete and accurate?
- Are time stamps recorded and consistent with KPIs?
- Are narratives present and consistent with source documents?
- Coding and data quality
- Is MedDRA coding consistent and appropriately documented?
- Are audit trails available for coding changes?
- Expedited reporting
- Are timelines met; check sample cases for end‑to‑end timelines?
- Is transmission format (E2B) validated?
- Aggregate reporting support
- Are deliverables on schedule and complete?
- IT and data integrity
- Are system access controls appropriate?
- Are backups, change logs and validation evidence available?
- CAPA and corrective actions
- Are previous CAPAs fully implemented and effective?
- Training
- Are personnel records current and aligned to activities?
- Subcontracting
- Are subcontractors identified, and are flow‑down obligations in place?
- Inspection readiness
- Is evidence readily available (minutes, KPIs, CAPA evidence, SDEAs)?
Audit report and follow-up
- Report should include objective, scope, findings (categorised by severity), evidence reference, CAPA requirements, target dates and responsible persons.
- CAPA register entry must be created for each finding; target dates and verification steps included.
- Follow‑up audits or verification activities should be scheduled based on severity.
Inspection relevance: Inspectors will examine audit reports, CAPA registers and evidence of effectiveness checks. They will verify whether audit scope corresponds to current risk and whether findings led to sustained improvement.
E. CAPA Register and Verification Evidence Template
Purpose: CAPAs must be actionable, timebound and include documented evidence of implementation and verification of effectiveness. Recurrent findings often result from weak CAPA design or lack of verification.
CAPA register fields (tabular)
| CAPA ID | Date opened | Origin (audit/KPI/event) | Description of issue | Root cause summary | Corrective action(s) | Preventive action(s) | Owner | Target date | Status | Evidence location | Verification method | Date verified |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CAPA‑2025‑045 | 2025‑02‑10 | Audit VEND‑01234 | Delayed forwarding of serious ICSRs | Lack of KPI monitoring and no escalation matrix | Implement automated forwarding within 24h; retrain staff; update SDEA | Monthly review of forwarding logs and KPI refinement | PV Vendor Manager | 2025‑03‑31 | Closed | CAPA folder / eTMF | Trend analysis of 3 months; sample recheck of cases | 2025‑06‑15 |
Verification evidence examples
- Implementation evidence:
- Updated SOP/SDEA with version and effective date.
- System change request and validation evidence (if automation implemented).
- Training records with attendee list and content.
- Signed deliverable acceptance from vendor.
- Effectiveness evidence:
- Trend charts (KPI performance) showing sustained improvement for pre‑defined period (commonly 3–6 months for operational CAPAs).
- Reaudit or focused independent verification report.
- Random sample rechecks with documented pass/fail results.
- Decrease in related complaint/incident rates.
- Documentation:
- Meeting minutes where CAPA approval and progress were discussed.
- Final CAPA close‑out report referencing evidence location and verification methodology.
Verification method guidance
- Define acceptance criteria for effectiveness verification (e.g., KPI in green for three consecutive months).
- Use independent reviewers for verification where possible (QA or internal audit).
- Document rationale for closure, including objective evidence.
Inspection relevance: Inspectors will request CAPA records and verification evidence. Vague statements of “CAPA implemented” without supporting evidence are frequent deficiencies.
F. Example Governance Meeting Pack — Minimum Contents
For each vendor governance meeting (periodic), maintain a meeting pack that is retained and searchable.
Minimum contents
- Agenda and attendees (with roles)
- Current vendor inventory extract (relevant vendor)
- KPI dashboard with trend data and thresholds highlighted
- Open CAPA list with status and evidence links
- Audit status (recent audits, outstanding actions)
- Change log (any contract/SDEA changes, system migrations)
- Risk register excerpts for the vendor
- Key incidents and regulatory notifications since last meeting
- Action log with owners and due dates
- Decisions and escalation notes, including QPPV inputs if applicable
- Signed minutes and reviewer approval
Inspection relevance: Inspectors commonly request meeting minutes to confirm governance activity. Minutes without clear decisions, owners and deadlines are inadequate.
G. Implementation Roadmap — Practical Steps to Create an Inspection‑Ready Package
- Assign ownership and accountability
- Nominate a named PV Vendor Manager and confirm QPPV oversight responsibilities.
- Document responsibilities in the vendor governance SOP.
- Build and stabilise the vendor inventory
- Populate the template, link contracts and SDEAs, and reconcile with procurement and PSMF.
- Review SDEAs and contracts
- Verify clauses align with real operations; amend SDEAs where discrepancies exist; maintain version history.
- Establish KPIs and thresholds
- Define KPIs, data sources, owners and thresholds; implement automated data extraction where feasible.
- Design audit programme
- Risk‑based audit frequency, scopes and resource allocation; schedule audits and track completion.
- Implement CAPA process
- CAPA register template; require evidence of implementation and independent effectiveness verification.
- Embed meeting cadence and documentation
- Regular vendor governance meetings; standardised meeting packs and minutes.
- Integrate change control
- Ensure change triggers update inventory, risk assessment, SDEA and audit schedule.
- Test inspection readiness
- Perform internal mock inspection: request documents as inspector would and validate retrieval time and completeness.
- Maintain continuous improvement
- Review processes after audits and inspections to address systemic gaps.
Timing and resource considerations
- Initial clean‑up (inventory and SDEA reconciliation): 3–6 months depending on portfolio size.
- KPI automation and audit scheduling: incremental — implement high‑risk vendors first.
- Ongoing maintenance: continuous; quarterly reconciliations and annual programme review are recommended.
H. Cross‑Referencing and Documentation Links
Ensure that each artefact is cross‑referenced and easily accessible for inspection:
- Vendor inventory entries link to contract/SDEA, latest audit report, KPI snapshots and CAPA entries.
- PSMF should reference vendor governance approach, inventory location and key vendors.
- SOPs should define processes for inventory maintenance, SDEA management, audits, KPI governance, CAPA and change control.
Inspection relevance: Inspectors will follow a document trail across artefacts. Lack of logical traceability commonly leads to findings.
I. Sample Evidence Checklist for Inspection Box
Prepare an inspection pack (electronic or physical) with the following items per critical vendor:
- Vendor inventory record (current)
- Signed contract and SDEA (latest version)
- Latest audit report and previous audit summary
- CAPA register entries arising from audits (including effectiveness evidence)
- KPI reports for the last 12 months (monthly/quarterly as applicable)
- Governance meeting minutes for last 12 months
- Change control records affecting the vendor (last 24 months)
- Named contacts and organisational chart
- Evidence of QPPV / senior PV involvement (reports, signatures)
- Training records for vendor staff performing PV activities (sample)
- System validation and data transfer evidence (if applicable)
- Subcontractor list and associated flow‑down clauses
Presentation guidance
- Use a folder structure that mirrors the inventory fields.
- Include an index page listing all documents and hyperlinks.
- For electronic submissions, ensure read‑only access and compatibility with regulatory inspection systems.
Inspection relevance: An organised inspection pack significantly reduces the risk of findings associated with missing evidence and demonstrates governance maturity.
This appendix is designed to be practical and inspection‑ready: populate the templates with operational data, maintain version control, and integrate the artefacts into your quality management system. These materials enable you to demonstrate effective oversight that is traceable, risk‑based and verifiable — the core elements inspectors expect when assessing outsourced pharmacovigilance activities.