Vendor Oversight for QPPVs

An advanced guide to vendor oversight from the QPPV perspective, including governance, risk management, escalation, inspections and organisational accountability.

Audio Lesson 9 min

Vendor Oversight for QPPVs

Introduction

Modern pharmacovigilance systems increasingly depend upon outsourced activities.

A typical Marketing Authorisation Holder may outsource:

As outsourcing expands, an important question emerges:

How can a QPPV maintain oversight of activities they do not directly perform?

This question sits at the centre of modern pharmacovigilance governance.

The answer is not direct operational involvement but effective, auditable oversight.

The QPPV's Role

The QPPV is responsible for oversight of the pharmacovigilance system. This responsibility differs from operational management. Operational teams perform activities; the QPPV maintains visibility regarding:

A useful distinction is: - Operations: perform the work. - Oversight: verify that the work is performed appropriately.

The QPPV primarily operates within the second category.

Outsourcing Does Not Remove QPPV Responsibilities

Outsourcing does not remove accountability. Although activities may be delegated, responsibility remains. The QPPV should therefore understand:

The objective is informed, evidence-based oversight rather than operational execution.

What the QPPV Needs to Know

The QPPV does not need to memorise every contract or KPI, but visibility regarding the following is essential:

The QPPV and Critical Vendors

Not all vendors require equal attention. QPPV visibility should be greatest where risk is highest, for example:

A useful question is:

If this vendor failed tomorrow, would pharmacovigilance compliance be affected?

If the answer is yes, the QPPV should understand the associated risks and controls.

Vendor Risk Through the QPPV Lens

QPPVs focus on compliance impact, patient safety impact, inspection risk and business continuity. Operational teams may focus more on workload and throughput. Both perspectives are complementary and together enable a complete view of vendor risk.

Governance Information the QPPV Should Receive

A practical governance framework provides the QPPV with visibility regarding:

The objective is meaningful visibility rather than information overload.

Vendor Dashboards for QPPVs

Dashboards can support oversight when designed for governance rather than operations.

Operational dashboards typically show work queues, volumes and resource metrics. QPPV dashboards should focus on:

Dashboards must be auditable: every metric should link to source data and evidence items that can be presented during inspections.

Vendor Audits and the QPPV

Although the QPPV may not perform audits, audit outcomes provide essential oversight information. Focus on:

Audit artefacts often reveal issues that are not visible through routine reporting.

CAPAs and the QPPV

A mature governance model ensures the QPPV has visibility of:

Persistent CAPA issues often indicate broader governance weaknesses and deserve QPPV attention.

The QPPV and SDEAs

Safety Data Exchange Agreements (SDEAs) define responsibilities across organisational boundaries. The QPPV should understand:

The objective is governance awareness and demonstrable accountability rather than contract negotiation.

Vendor Oversight and the PSMF

The Pharmacovigilance System Master File (PSMF) provides a structured description of the PV system. The PSMF should answer:

A well-maintained PSMF supports effective oversight and inspection readiness.

Common QPPV Oversight Failures

Common weaknesses include:

These weaknesses frequently become apparent during inspections.

Inspection Perspective

Inspectors commonly explore:

Inspectors expect evidence-based oversight, not rote recitation. The aim is to demonstrate control and traceability.

What Inspectors Want to See

Strong inspection performance typically includes:

Inspectors generally seek confidence that outsourced activities remain under organisational control.

Characteristics of Mature QPPV Oversight

High-performing organisations demonstrate:

These characteristics support both compliance and inspection readiness.

A Practical Question for Every QPPV

A useful self-assessment question is:

If a critical vendor experienced a major compliance failure today, how quickly would I know?

The answer often reveals the maturity of the oversight framework. Strong organisations provide rapid visibility; weak organisations discover issues much later.

Inspection-ready Vendor Oversight Checklist

This concise, inspection-ready checklist converts conceptual guidance into auditable actions and expected evidence. It is designed for inclusion in the PSMF annexes and vendor oversight folders.

For each checklist item below, the QPPV should be able to produce the corresponding evidence within a reasonable timeframe (typically 24–72 hours during an inspection).

Use this checklist during governance meetings and include the most relevant evidence links in the PSMF or an inspection pack so that retrieval is fast and defensible.

Sample Vendor Dashboard: KPIs, Thresholds and Evidence Items

The following sample dashboard is designed for QPPV-level oversight of a critical case processing vendor. It emphasises indicators that have regulatory and inspection relevance. Values and thresholds should be adapted to specific contracts and regulatory expectations (e.g., 15-day expedited reporting requirements per applicable legislation).

Note on dashboard use: - Each KPI must link back to source data (safety database exports, audit reports, CAPA logs). - Thresholds should be set in collaboration with PV quality, legal and the vendor. - Colour thresholds (Green/Amber/Red) should trigger defined governance responses and be recorded in meeting minutes.

Sample KPI dashboard (monthly snapshot):

KPI Definition / Calculation Target / Thresholds Evidence items (inspection-ready) Owner & Frequency
Expedited report timeliness (serious, unexpected) % of ICSRs submitted to regulator within required timeline (e.g., 15 calendar days) Green β‰₯98%; Amber 95–97.9%; Red <95% Database report extract (timestamped), email/sign-off trails, regulatory submission logs Vendor QP / MAH reviewer β€” Monthly
Case intake completeness % ICSRs with mandatory fields completed at intake (patient age, event description, reporter) Green β‰₯99%; Amber 97–98.9%; Red <97% Intake report, sample case exports, SOP for intake, training records Vendor operations β€” Monthly
Coding accuracy (MedDRA) % of primary MedDRA term concordant with MAH adjudication on sample Green β‰₯98%; Amber 95–97.9%; Red <95% Coding QA sample results, coding SOP, sample-case comparisons QA lead β€” Quarterly
Duplicate rate % duplicate cases detected post‑de‑duplication Green ≀2%; Amber 2.1–5%; Red >5% Duplicate detection logs, sample case pairs, de-duplication algorithm description Vendor database admin β€” Monthly
Query turnaround time Median time to resolve critical queries (days) Green ≀3 days; Amber 3–7; Red >7 Query log exports, sample case timelines, SOP Vendor operations β€” Monthly
Literature screening coverage % of relevant journals/databases screened per agreed scope Green β‰₯100%; Amber 90–99%; Red <90% Literature search logs, LSR reports, search strategy documents Vendor literature lead β€” Monthly
Audit finding rate (Major/Critical) Number of major/critical findings in last 24 months Green 0; Amber 1; Red β‰₯2 Audit reports, provider responses, CAPAs Head of QA β€” Quarterly
CAPA overdue items Number of vendor CAPAs overdue beyond agreed date Green 0; Amber 1–2; Red β‰₯3 CAPA tracker export, evidence attachments, management minutes Vendor QA / MAH CAPA owner β€” Monthly
BCP test success % of successful BCP tests in past 12 months Green β‰₯100% of scheduled; Amber 75–99%; Red <75% BCP test reports, corrective actions, business impact assessments Vendor continuity lead β€” Annual
System availability (safety database) % uptime (production) Green β‰₯99.9%; Amber 99–99.89%; Red <99% System availability reports, incident reports, hosting SLA Vendor IT / MAH IT β€” Monthly
Regulatory submission rejection rate % submissions rejected by regulator due to format/data issues Green 0%; Amber 0–1%; Red >1% Submission logs, rejection notices, corrective actions Regulatory affairs β€” Monthly
Training compliance (PV-specific) % of vendor personnel in critical functions with current training Green β‰₯98%; Amber 95–97.9%; Red <95% Training matrices, certificates, training materials Vendor HR / MAH oversight β€” Annually

For each KPI, the dashboard should provide: - Current value and trend (3–12 months) - Colour status per threshold - Link to underlying evidence (e.g., file ID in document management system) - Action required if Amber/Red (automated escalation or trigger to governance meeting) - Date and signature of MAH reviewer (evidence of oversight)

Sample vendor-level evidence mapping (what to present for each KPI during an inspection):

Practical Implementation Details

Turning the checklist and dashboard into operational, inspection-ready tools requires deliberate implementation steps:

  1. Data architecture and single source of truth
  2. Identify authoritative sources (safety database, vendor QM systems, audit repository, CAPA tracker).
  3. Ensure unique identifiers for cases, audits and CAPAs so evidence links reliably.
  4. Automate extracts where possible to reduce manual errors and create timestamped exports.

  5. Standardise KPI definitions

  6. Document calculation formulae, denominator/numerator definitions and any exclusions.
  7. Version-control KPI definitions and publish in the oversight SOP or the PSMF annex.

  8. Define thresholds and governance actions

  9. For each KPI set clear threshold bands and define automatic actions (e.g., trigger vendor corrective actions, escalate to QPPV, convene emergency governance meeting).
  10. Map threshold breaches to owners and required evidence for resolution.

  11. Evidence management and retrieval

  12. Maintain an inspection pack or indexed evidence repository accessible to the QPPV and inspection teams.
  13. Attach evidence references to each KPI on the dashboard (file IDs, URLs, copies with access logs).
  14. Retain evidence per records retention policy and ensure traceability.

  15. Governance cadence and sign-off

  16. Establish meeting schedules: monthly vendor performance, quarterly governance, annual strategy/audit planning.
  17. Require QPPV or delegated PV Head sign-off on monthly dashboards and significant corrective actions.
  18. Record decisions and rationales in meeting minutes and link to the dashboard evidence.

  19. Automation and validation

  20. Where possible automate dashboard generation from validated extracts.
  21. Validate dashboard calculations periodically (e.g., annually or after significant system changes).
  22. Include dashboard and evidence checks in internal audits.

  23. Inspection readiness drills

  24. Run annual or biannual mock inspections focusing on vendor oversight; test evidence retrieval and QPPV responses.
  25. Update the inspection pack based on drill findings.

  26. Integration with the PSMF and SDEAs

  27. Ensure the PSMF references the vendor dashboard, critical vendor list and provides links to inspection packs.
  28. Ensure SDEAs reflect KPI expectations and data access/retention requirements to support oversight.

Regulatory Context and Inspection Relevance

Regulatory frameworks (e.g., EMA GVP Modules I, II and III; ICH Q9; national PV legislation) expect that MAHs maintain a pharmacovigilance system that is effective regardless of outsourcing.

Key regulatory expectations relevant to the checklist and dashboard: - The MAH remains responsible for pharmacovigilance obligations irrespective of delegation (GVP Module I). - The PSMF must accurately describe the PV system including outsourced activities and quality measures (GVP Module II). - Inspections will seek to determine whether oversight is sufficient to ensure compliance (GVP Module III).

Practical inspection relevance: - Inspectors commonly request the PSMF, a vendor register, recent audit reports, CAPA evidence, representative case files and evidence of QPPV oversight (meeting minutes, dashboard sign-offs). - A well-prepared dashboard that links KPIs to source evidence shortens inspection time and demonstrates effective control. - Demonstrable escalation actions with timelines and outcomes (e.g., email trails, minutes, CAPA evidence) are persuasive evidence of governance.

Governance Discussion

Effective governance converts dashboard signals into timely, documented decisions:

Final Notes on Auditability

Auditors and inspectors place high value on: - Consistency between documents (PSMF, vendor register, SDEAs, dashboards and minutes). - Direct links between metrics and evidence items. - Demonstrated review and decision-making by named individuals (QPPV sign-off). - Records that show timely escalation and verification of CAPA effectiveness.

By implementing the inspection-ready checklist and a linked, evidence-based vendor dashboard, QPPVs can convert conceptual oversight into actionable, auditable controls that satisfy regulatory expectations and materially reduce vendor-related risk.

Key Takeaways

References

  1. EMA Good Pharmacovigilance Practices (GVP) Module I – Pharmacovigilance Systems and Their Quality Systems.
  2. EMA Good Pharmacovigilance Practices (GVP) Module II – Pharmacovigilance System Master File.
  3. EMA Good Pharmacovigilance Practices (GVP) Module III – Pharmacovigilance Inspections.
  4. Regulation (EC) No 726/2004.
  5. Directive 2001/83/EC.
  6. Commission Implementing Regulation (EU) No 520/2012.
  7. ICH Q9 Quality Risk Management.
  8. ICH E2E Pharmacovigilance Planning.

Last reviewed: 2026-06-11