Vendor Oversight for QPPVs
- Vendor Oversight for QPPVs
- Introduction
- The QPPV's Role
- Outsourcing Does Not Remove QPPV Responsibilities
- What the QPPV Needs to Know
- The QPPV and Critical Vendors
- Vendor Risk Through the QPPV Lens
- Governance Information the QPPV Should Receive
- Vendor Dashboards for QPPVs
- Vendor Audits and the QPPV
- CAPAs and the QPPV
- The QPPV and SDEAs
- Vendor Oversight and the PSMF
- Common QPPV Oversight Failures
- Inspection Perspective
- What Inspectors Want to See
- Characteristics of Mature QPPV Oversight
- A Practical Question for Every QPPV
- Inspection-ready Vendor Oversight Checklist
- Sample Vendor Dashboard: KPIs, Thresholds and Evidence Items
- Practical Implementation Details
- Regulatory Context and Inspection Relevance
- Governance Discussion
- Final Notes on Auditability
- Key Takeaways
- References
Introduction
Modern pharmacovigilance systems increasingly depend upon outsourced activities.
A typical Marketing Authorisation Holder may outsource:
- Case processing
- Literature surveillance
- Medical information
- Aggregate reporting
- Signal management support
- Safety database hosting
As outsourcing expands, an important question emerges:
How can a QPPV maintain oversight of activities they do not directly perform?
This question sits at the centre of modern pharmacovigilance governance.
The answer is not direct operational involvement but effective, auditable oversight.
The QPPV's Role
The QPPV is responsible for oversight of the pharmacovigilance system. This responsibility differs from operational management. Operational teams perform activities; the QPPV maintains visibility regarding:
- Compliance
- Governance
- Risk
- Escalation
- System effectiveness
A useful distinction is: - Operations: perform the work. - Oversight: verify that the work is performed appropriately.
The QPPV primarily operates within the second category.
Outsourcing Does Not Remove QPPV Responsibilities
Outsourcing does not remove accountability. Although activities may be delegated, responsibility remains. The QPPV should therefore understand:
- Which activities are outsourced and why
- Which vendors perform them and which are critical
- How performance and compliance are monitored
- How issues are escalated and resolved
The objective is informed, evidence-based oversight rather than operational execution.
What the QPPV Needs to Know
The QPPV does not need to memorise every contract or KPI, but visibility regarding the following is essential:
- Vendor landscape (who, what, criticality)
- Risk profile (high-risk vendors, critical dependencies, vulnerabilities)
- Governance structure (ownership, escalation pathways, review mechanisms)
- Compliance performance (trends, significant deficiencies, emerging concerns)
The QPPV and Critical Vendors
Not all vendors require equal attention. QPPV visibility should be greatest where risk is highest, for example:
- Safety database providers
- Case processing vendors
- Literature surveillance vendors
- Aggregate reporting providers
A useful question is:
If this vendor failed tomorrow, would pharmacovigilance compliance be affected?
If the answer is yes, the QPPV should understand the associated risks and controls.
Vendor Risk Through the QPPV Lens
QPPVs focus on compliance impact, patient safety impact, inspection risk and business continuity. Operational teams may focus more on workload and throughput. Both perspectives are complementary and together enable a complete view of vendor risk.
Governance Information the QPPV Should Receive
A practical governance framework provides the QPPV with visibility regarding:
- Critical vendor list (approved and active)
- Significant deviations and incidents
- Audit outcomes and follow-up
- CAPA status and effectiveness checks
- Escalations requiring management attention
The objective is meaningful visibility rather than information overload.
Vendor Dashboards for QPPVs
Dashboards can support oversight when designed for governance rather than operations.
Operational dashboards typically show work queues, volumes and resource metrics. QPPV dashboards should focus on:
- Compliance indicators (timeliness of expedited reports, completeness of ICSRs)
- Risk indicators (BCP readiness, single points of failure)
- Escalations and unresolved incidents
- Audit outcomes and recurrent findings
- CAPA performance and overdue actions
Dashboards must be auditable: every metric should link to source data and evidence items that can be presented during inspections.
Vendor Audits and the QPPV
Although the QPPV may not perform audits, audit outcomes provide essential oversight information. Focus on:
- Critical and major findings
- Repeat findings across vendors
- Major CAPAs and evidence of effectiveness
- Systemic weaknesses that affect multiple vendors or the PV system overall
Audit artefacts often reveal issues that are not visible through routine reporting.
CAPAs and the QPPV
A mature governance model ensures the QPPV has visibility of:
- Significant CAPAs
- Overdue CAPAs
- Repeat deficiencies
- Effectiveness concerns
Persistent CAPA issues often indicate broader governance weaknesses and deserve QPPV attention.
The QPPV and SDEAs
Safety Data Exchange Agreements (SDEAs) define responsibilities across organisational boundaries. The QPPV should understand:
- Which relationships require SDEAs
- Which responsibilities are shared or retained
- The interplay of SDEAs with the PSMF and contracts
The objective is governance awareness and demonstrable accountability rather than contract negotiation.
Vendor Oversight and the PSMF
The Pharmacovigilance System Master File (PSMF) provides a structured description of the PV system. The PSMF should answer:
- Which vendors perform critical activities?
- How is oversight maintained?
- How are responsibilities allocated and evidenced?
- How are risks controlled?
A well-maintained PSMF supports effective oversight and inspection readiness.
Common QPPV Oversight Failures
Common weaknesses include:
- Limited vendor visibility
- Weak escalation pathways
- Over-reliance on operational reports
- Insufficient risk focus on critical vendors
- Weak governance integration between vendor oversight and PV governance
These weaknesses frequently become apparent during inspections.
Inspection Perspective
Inspectors commonly explore:
- Does the QPPV understand outsourced activities?
- Can the QPPV explain oversight arrangements?
- Does the QPPV receive significant vendor information?
- Can the QPPV discuss critical risks and recent incidents?
Inspectors expect evidence-based oversight, not rote recitation. The aim is to demonstrate control and traceability.
What Inspectors Want to See
Strong inspection performance typically includes:
- Clear vendor inventories and criticality assessments
- Risk-based oversight documented in governance records
- Effective escalation and decision-making records
- QPPV visibility and sign-off where applicable
- Accessible and auditable documentation (SDEAs, contracts, audit reports, CAPA files, management meeting minutes)
Inspectors generally seek confidence that outsourced activities remain under organisational control.
Characteristics of Mature QPPV Oversight
High-performing organisations demonstrate:
- Visibility of outsourced activities
- Risk awareness and mitigation plans
- Governance integration with the broader PV system
- Effective escalation routes
- Continuous review and improvement cycles
These characteristics support both compliance and inspection readiness.
A Practical Question for Every QPPV
A useful self-assessment question is:
If a critical vendor experienced a major compliance failure today, how quickly would I know?
The answer often reveals the maturity of the oversight framework. Strong organisations provide rapid visibility; weak organisations discover issues much later.
Inspection-ready Vendor Oversight Checklist
This concise, inspection-ready checklist converts conceptual guidance into auditable actions and expected evidence. It is designed for inclusion in the PSMF annexes and vendor oversight folders.
For each checklist item below, the QPPV should be able to produce the corresponding evidence within a reasonable timeframe (typically 24β72 hours during an inspection).
- Vendor Inventory and Criticality
- Item: Up-to-date vendor register identifying activity, criticality (high/medium/low), service start date and contract owner.
- Evidence: Vendor register export, PSMF cross-reference, contracts/SDEAs, last update timestamp.
- Frequency: Quarterly; ad hoc when new vendors engaged.
-
Inspection relevance: Demonstrates awareness of outsourced scope and critical dependencies.
-
SDEAs and Contracts
- Item: Signed SDEAs or contract clauses defining responsibilities, timelines for expedited reporting, data ownership and audit rights.
- Evidence: Executed contract/SDEA, annexes with PV responsibilities, signature pages, version history.
- Frequency: On change; reviewed annually.
-
Inspection relevance: Shows formal allocation of obligations and audit access.
-
Data Flow Diagrams and Responsibility Matrices
- Item: Flow diagrams showing data movement (e.g., from call centre β case processor β safety database β MAH), and a RACI or responsibility matrix for key activities.
- Evidence: PSMF diagrams, responsibility matrix document, recent approvals.
- Frequency: Annually or at major change.
-
Inspection relevance: Demonstrates how the MAH maintains control and oversight of data lifecycle.
-
KPIs and Dashboard Reporting
- Item: Governance dashboard(es) for each critical vendor with defined KPIs, thresholds and data sources.
- Evidence: Dashboard exports (PDF with timestamp), source reports, meeting minutes where KPI trends were discussed.
- Frequency: Monthly (dashboard), quarterly review (governance meeting).
-
Inspection relevance: Shows ongoing monitoring and triggers for escalation.
-
Audit Schedule and Outcomes
- Item: Risk-based audit plan showing recent audits, open/closed CAPAs and follow-up evidence.
- Evidence: Audit reports, management responses, CAPA logs, evidence of CAPA effectiveness checks.
- Frequency: As per audit plan (e.g., every 1β3 years based on risk).
-
Inspection relevance: Demonstrates the organisation conducts independent assessments and remediates issues.
-
CAPA Management
- Item: CAPA register for vendor-related findings with owners, due dates, status and evidence-of-effectiveness.
- Evidence: CAPA tracker, evidence attachments (training records, SOP updates, re-audit), closure approvals.
- Frequency: Continuous; reviewed monthly in oversight governance.
-
Inspection relevance: Shows how corrective actions are tracked and verified.
-
Escalation and Incident Response
- Item: Documented escalation criteria, incident reporting pathways and evidence of incidents escalated to MAH/QPPV.
- Evidence: Incident/major deviation reports, escalation emails/meeting minutes, root cause analyses, BCP invocation records.
- Frequency: On incident; table-top tests annually.
-
Inspection relevance: Demonstrates timely detection, escalation and response to vendor failures.
-
Business Continuity and Disaster Recovery
- Item: BCP/DR plans for critical vendors, and evidence of recent tests.
- Evidence: BCP documents, test reports, corrective actions from tests, service continuity evidence.
- Frequency: Annual test; ad hoc when risk changes.
-
Inspection relevance: Demonstrates preparedness for interruptions affecting PV obligations.
-
System Validation and Change Control
- Item: Evidence of validation for safety databases and significant vendor IT changes plus change control records.
- Evidence: Validation summary reports, test scripts/results, change control records, traceability matrices.
- Frequency: At implementation and for major changes.
-
Inspection relevance: Shows technical controls supporting data integrity and reporting obligations.
-
Personnel and Training
- Item: Vendor personnel qualifications for critical roles, and evidence of PV-specific training and oversight (e.g., SOPs, QMS alignment).
- Evidence: Training matrices, CVs for key personnel, training records, subcontractor lists.
- Frequency: Annually; on staff change.
-
Inspection relevance: Demonstrates vendor capability and controls over competencies.
-
Performance and Quality Trends
- Item: Trend analyses showing KPI performance over time, emergent patterns, and decisions made.
- Evidence: Trend charts, governance meeting minutes, decisions and follow-up actions.
- Frequency: Quarterly reviews.
-
Inspection relevance: Demonstrates proactive oversight and continuous improvement.
-
Regulatory Correspondence and Reporting
- Item: Copies of regulatory reports submitted, evidence of MAH sign-off for expedited reports, and logs for regulatory queries.
- Evidence: CIOMS/E2B submissions, submission logs from safety database, sign-off records, emails relating to regulator interactions.
- Frequency: Continuous; retained per records policy.
-
Inspection relevance: Demonstrates that regulatory obligations are being fulfilled and evidence of MAH control over submissions.
-
Escalated Issues Log
- Item: Chronological log of issues escalated to QPPV/Head of PV, including resolution outcomes.
- Evidence: Escalation log, supporting documents, closure evidence, lessons learned documentation.
- Frequency: Continuous; reviewed at governance meetings.
- Inspection relevance: Demonstrates visibility of significant problems and documented decision-making.
Use this checklist during governance meetings and include the most relevant evidence links in the PSMF or an inspection pack so that retrieval is fast and defensible.
Sample Vendor Dashboard: KPIs, Thresholds and Evidence Items
The following sample dashboard is designed for QPPV-level oversight of a critical case processing vendor. It emphasises indicators that have regulatory and inspection relevance. Values and thresholds should be adapted to specific contracts and regulatory expectations (e.g., 15-day expedited reporting requirements per applicable legislation).
Note on dashboard use: - Each KPI must link back to source data (safety database exports, audit reports, CAPA logs). - Thresholds should be set in collaboration with PV quality, legal and the vendor. - Colour thresholds (Green/Amber/Red) should trigger defined governance responses and be recorded in meeting minutes.
Sample KPI dashboard (monthly snapshot):
| KPI | Definition / Calculation | Target / Thresholds | Evidence items (inspection-ready) | Owner & Frequency |
|---|---|---|---|---|
| Expedited report timeliness (serious, unexpected) | % of ICSRs submitted to regulator within required timeline (e.g., 15 calendar days) | Green β₯98%; Amber 95β97.9%; Red <95% | Database report extract (timestamped), email/sign-off trails, regulatory submission logs | Vendor QP / MAH reviewer β Monthly |
| Case intake completeness | % ICSRs with mandatory fields completed at intake (patient age, event description, reporter) | Green β₯99%; Amber 97β98.9%; Red <97% | Intake report, sample case exports, SOP for intake, training records | Vendor operations β Monthly |
| Coding accuracy (MedDRA) | % of primary MedDRA term concordant with MAH adjudication on sample | Green β₯98%; Amber 95β97.9%; Red <95% | Coding QA sample results, coding SOP, sample-case comparisons | QA lead β Quarterly |
| Duplicate rate | % duplicate cases detected postβdeβduplication | Green β€2%; Amber 2.1β5%; Red >5% | Duplicate detection logs, sample case pairs, de-duplication algorithm description | Vendor database admin β Monthly |
| Query turnaround time | Median time to resolve critical queries (days) | Green β€3 days; Amber 3β7; Red >7 | Query log exports, sample case timelines, SOP | Vendor operations β Monthly |
| Literature screening coverage | % of relevant journals/databases screened per agreed scope | Green β₯100%; Amber 90β99%; Red <90% | Literature search logs, LSR reports, search strategy documents | Vendor literature lead β Monthly |
| Audit finding rate (Major/Critical) | Number of major/critical findings in last 24 months | Green 0; Amber 1; Red β₯2 | Audit reports, provider responses, CAPAs | Head of QA β Quarterly |
| CAPA overdue items | Number of vendor CAPAs overdue beyond agreed date | Green 0; Amber 1β2; Red β₯3 | CAPA tracker export, evidence attachments, management minutes | Vendor QA / MAH CAPA owner β Monthly |
| BCP test success | % of successful BCP tests in past 12 months | Green β₯100% of scheduled; Amber 75β99%; Red <75% | BCP test reports, corrective actions, business impact assessments | Vendor continuity lead β Annual |
| System availability (safety database) | % uptime (production) | Green β₯99.9%; Amber 99β99.89%; Red <99% | System availability reports, incident reports, hosting SLA | Vendor IT / MAH IT β Monthly |
| Regulatory submission rejection rate | % submissions rejected by regulator due to format/data issues | Green 0%; Amber 0β1%; Red >1% | Submission logs, rejection notices, corrective actions | Regulatory affairs β Monthly |
| Training compliance (PV-specific) | % of vendor personnel in critical functions with current training | Green β₯98%; Amber 95β97.9%; Red <95% | Training matrices, certificates, training materials | Vendor HR / MAH oversight β Annually |
For each KPI, the dashboard should provide: - Current value and trend (3β12 months) - Colour status per threshold - Link to underlying evidence (e.g., file ID in document management system) - Action required if Amber/Red (automated escalation or trigger to governance meeting) - Date and signature of MAH reviewer (evidence of oversight)
Sample vendor-level evidence mapping (what to present for each KPI during an inspection):
- KPI: Expedited report timeliness
- Evidence: E2B export for period, filter for serious/unexpected cases, timestamps for event onset/receipt/MAH notification/regulatory submission, dashboard query script, MAH sign-off email for sample cases.
- KPI: CAPA overdue items
- Evidence: CAPA register with history, attachments (training records/system changes), meeting minutes approving extensions, evidence of escalations to QPPV.
- KPI: Audit finding rate
- Evidence: Audit report(s) with findings classification, vendor response plan, CAPA evidence, follow-up audit or verification evidence.
Practical Implementation Details
Turning the checklist and dashboard into operational, inspection-ready tools requires deliberate implementation steps:
- Data architecture and single source of truth
- Identify authoritative sources (safety database, vendor QM systems, audit repository, CAPA tracker).
- Ensure unique identifiers for cases, audits and CAPAs so evidence links reliably.
-
Automate extracts where possible to reduce manual errors and create timestamped exports.
-
Standardise KPI definitions
- Document calculation formulae, denominator/numerator definitions and any exclusions.
-
Version-control KPI definitions and publish in the oversight SOP or the PSMF annex.
-
Define thresholds and governance actions
- For each KPI set clear threshold bands and define automatic actions (e.g., trigger vendor corrective actions, escalate to QPPV, convene emergency governance meeting).
-
Map threshold breaches to owners and required evidence for resolution.
-
Evidence management and retrieval
- Maintain an inspection pack or indexed evidence repository accessible to the QPPV and inspection teams.
- Attach evidence references to each KPI on the dashboard (file IDs, URLs, copies with access logs).
-
Retain evidence per records retention policy and ensure traceability.
-
Governance cadence and sign-off
- Establish meeting schedules: monthly vendor performance, quarterly governance, annual strategy/audit planning.
- Require QPPV or delegated PV Head sign-off on monthly dashboards and significant corrective actions.
-
Record decisions and rationales in meeting minutes and link to the dashboard evidence.
-
Automation and validation
- Where possible automate dashboard generation from validated extracts.
- Validate dashboard calculations periodically (e.g., annually or after significant system changes).
-
Include dashboard and evidence checks in internal audits.
-
Inspection readiness drills
- Run annual or biannual mock inspections focusing on vendor oversight; test evidence retrieval and QPPV responses.
-
Update the inspection pack based on drill findings.
-
Integration with the PSMF and SDEAs
- Ensure the PSMF references the vendor dashboard, critical vendor list and provides links to inspection packs.
- Ensure SDEAs reflect KPI expectations and data access/retention requirements to support oversight.
Regulatory Context and Inspection Relevance
Regulatory frameworks (e.g., EMA GVP Modules I, II and III; ICH Q9; national PV legislation) expect that MAHs maintain a pharmacovigilance system that is effective regardless of outsourcing.
Key regulatory expectations relevant to the checklist and dashboard: - The MAH remains responsible for pharmacovigilance obligations irrespective of delegation (GVP Module I). - The PSMF must accurately describe the PV system including outsourced activities and quality measures (GVP Module II). - Inspections will seek to determine whether oversight is sufficient to ensure compliance (GVP Module III).
Practical inspection relevance: - Inspectors commonly request the PSMF, a vendor register, recent audit reports, CAPA evidence, representative case files and evidence of QPPV oversight (meeting minutes, dashboard sign-offs). - A well-prepared dashboard that links KPIs to source evidence shortens inspection time and demonstrates effective control. - Demonstrable escalation actions with timelines and outcomes (e.g., email trails, minutes, CAPA evidence) are persuasive evidence of governance.
Governance Discussion
Effective governance converts dashboard signals into timely, documented decisions:
- Roles and responsibilities
- QPPV: ultimate oversight and sign-off for PV-critical matters; recipient of escalations and member/chair of governance meetings when required.
- Head of PV/VP RA: operational governance owner for vendor performance reporting and escalation execution.
- Vendor Oversight Committee (VOC) or PV Governance Board: periodic review of critical vendor performance, approval of remediation plans, and endorsement of strategic vendor changes.
-
Vendor relationship owner (MAH) and vendor account manager: day-to-day operational interface and first line escalation.
-
Decision-making and escalation
- Define clear escalation pathways based on KPI thresholds (e.g., vendor-level corrective action for Amber; VOC review for Red).
- Document who can close CAPAs and the evidence required for closure.
-
Ensure minutes capture decisions, rationales and assigned owners with deadlines.
-
Independence and challenge
- QA function should provide independent challenge to operational reporting and vendor self-assessments.
-
Use independent audits to validate vendor performance and the reliability of dashboard metrics.
-
Continuous improvement
- Periodically reassess KPI relevance, thresholds and data sources.
- Use trend analyses to move from reactive remediation to proactive risk reduction.
Final Notes on Auditability
Auditors and inspectors place high value on: - Consistency between documents (PSMF, vendor register, SDEAs, dashboards and minutes). - Direct links between metrics and evidence items. - Demonstrated review and decision-making by named individuals (QPPV sign-off). - Records that show timely escalation and verification of CAPA effectiveness.
By implementing the inspection-ready checklist and a linked, evidence-based vendor dashboard, QPPVs can convert conceptual oversight into actionable, auditable controls that satisfy regulatory expectations and materially reduce vendor-related risk.
Key Takeaways
- The QPPV is responsible for oversight rather than operational execution.
- Outsourcing activities does not remove accountability.
- Convert oversight into auditable controls: vendor lists, SDEAs, dashboards, audits, CAPAs and governance meeting records.
- Use the inspection-ready checklist and evidence-mapped dashboard to demonstrate control and responsiveness.
- Ensure governance defines owners, thresholds and escalation actions, and that all evidence is retrievable for inspection.
- Mature organisations treat vendor oversight as a core, evidence-based PV governance responsibility.
References
- EMA Good Pharmacovigilance Practices (GVP) Module I β Pharmacovigilance Systems and Their Quality Systems.
- EMA Good Pharmacovigilance Practices (GVP) Module II β Pharmacovigilance System Master File.
- EMA Good Pharmacovigilance Practices (GVP) Module III β Pharmacovigilance Inspections.
- Regulation (EC) No 726/2004.
- Directive 2001/83/EC.
- Commission Implementing Regulation (EU) No 520/2012.
- ICH Q9 Quality Risk Management.
- ICH E2E Pharmacovigilance Planning.