What is a Pharmacovigilance Audit?
- What is a Pharmacovigilance Audit?
- Introduction
- What Is a Pharmacovigilance Audit?
- Key Characteristics of Audits
- Why Pharmacovigilance Audits Exist
- Audits Versus Inspections
- Audits Versus Monitoring
- The Purpose of Auditing
- The Audit Lifecycle
- Audit Scope
- Risk-Based Auditing
- Audit Findings
- CAPAs
- The QPPV Perspective
- Inspection Perspective
- Common Misconceptions
- Characteristics of Effective Audits
- Governance of an Audit Programme
- Regulatory Context
- Practical Implementation Details
- Inspection‑Ready Checklist
- Inspection Relevance Mapping
- Audit Evidence Examples — Concrete Samples
- Templated Audit Report (Inspection‑Ready)
- CAPA Verification Criteria — Detailed Guidance
- Practical Examples of CAPA Verification Evidence
- Audit Follow‑Up and Trending
- Inspection Relevance — What Inspectors Look For
- Key Takeaways
- References
Introduction
Pharmacovigilance systems are built upon trust.
Regulators trust that Marketing Authorisation Holders have established effective systems to:
- Collect safety information
- Evaluate risks
- Monitor benefit–risk balance
- Meet regulatory obligations
- Protect patients
However, trust alone is insufficient.
Organisations must periodically verify that their systems are functioning as intended. This is the role of pharmacovigilance auditing.
A pharmacovigilance audit provides independent assessment of whether the pharmacovigilance system is operating effectively and whether risks are being managed appropriately.
What Is a Pharmacovigilance Audit?
A pharmacovigilance audit is a systematic, independent and documented assessment of pharmacovigilance activities. The objective is to determine whether:
- Processes are appropriately designed.
- Procedures are followed.
- Controls are functioning.
- Risks are managed.
- Regulatory obligations are met.
Audits evaluate both:
Compliance
Are requirements being met?
Effectiveness
Are controls actually working?
This distinction is important. A process may be compliant on paper while remaining ineffective in practice.
Key Characteristics of Audits
Several characteristics distinguish audits from routine operational activities.
Systematic
Audits follow a defined methodology. Activities are planned and documented.
Independent
Auditors maintain objectivity. They should not assess their own work.
Evidence‑Based
Conclusions are supported by verifiable evidence rather than assumptions.
Risk‑Focused
Attention is directed toward areas creating the greatest risk.
These principles support credibility and consistency.
Why Pharmacovigilance Audits Exist
All systems contain risk.
Even well‑managed organisations may experience:
- Process failures
- Human errors
- Technology issues
- Governance weaknesses
- Compliance gaps
Audits help identify these issues before they become:
- Regulatory findings
- Inspection observations
- Patient safety concerns
A useful way to view audits is:
Audits provide assurance that controls continue to operate effectively.
Audits Versus Inspections
Although both audits and inspections assess pharmacovigilance systems, their purpose differs.
| Audit | Inspection |
|---|---|
| Conducted by or on behalf of the organisation | Conducted by regulators |
| Focuses on assurance and improvement | Focuses on regulatory compliance |
| Part of internal governance | Part of regulatory oversight |
| Continuous activity | Periodic regulatory activity |
A strong audit programme improves inspection readiness. However, audits should not exist solely to prepare for inspections.
Audits Versus Monitoring
Audits and monitoring are different activities.
Monitoring
Usually focuses on ongoing operational performance. Examples:
- KPI review
- Compliance monitoring
- Trend analysis
Auditing
Provides independent assessment of system effectiveness.
Monitoring asks:
What is happening?
Auditing asks:
Why is it happening and are controls effective?
Both activities are important and complementary.
The Purpose of Auditing
Audits provide assurance, inform management and guide improvement. Audits help answer:
- Are controls effective?
- Are risks understood?
- Are processes functioning?
- Are improvements required?
- Does management have reliable visibility?
The strongest audit programmes support organisational learning rather than simply generating findings.
The Audit Lifecycle
Most pharmacovigilance audits follow a structured lifecycle.
Planning
Define objectives, scope, risk rationale, resource needs, audit team composition, timeline and reporting lines. Establish independence and conflict‑of‑interest checks.
Preparation
Assemble background documentation (PSMF, SOPs, previous audit and inspection reports, CAPA logs, KPI trends), create the document request list and sampling plan, and prepare checklists and interview guides.
Fieldwork
Collect and evaluate evidence: interviews, document review, system extracts, case re‑reviews, observation of processes and meetings. Record evidence with unique identifiers and retain original extracts/screenshots.
Reporting
Document factual observations, risk evaluation, root cause analysis, and recommended CAPAs. Provide graded findings (critical/major/minor/observation) and an executive summary for senior management.
CAPAs
Agree corrective and preventive actions with owners, including SMART objectives, resources and timelines.
Follow‑Up
Verify implementation and effectiveness of CAPAs with evidence and metrics. Determine whether re‑audit or monitoring is required.
Each stage contributes to audit quality and inspection readiness.
Audit Scope
Audit scope varies according to objectives. Common scopes include:
- Case Processing (ICSR lifecycle, SAE reporting)
- Signal Management
- Aggregate Reporting (PSUR/DSUR/Periodic reports)
- Vendor Oversight and Third‑Party Management
- Pharmacovigilance System Master File (PSMF)
- Quality Systems (training, CAPAs and governance)
- IT Systems Supporting PV (E2B gateway, safety databases)
- Local PV compliance in affiliate countries
Scope selection should be risk‑based, dynamic and documented.
Risk-Based Auditing
Modern audit programmes increasingly use risk‑based approaches. This recognises that not all activities create equal risk. Factors commonly considered include:
- Patient safety impact
- Regulatory impact
- Operational complexity
- Outsourcing dependency
- Inspection history
- Volume of activity
Higher‑risk activities receive greater audit attention and more rigorous sampling.
For additional discussion see: [[risk-based-audit-planning]]
Audit Findings
Audit findings identify weaknesses, risks or opportunities for improvement.
Common categories include:
- Critical Findings — Significant immediate risk to patient safety or regulatory non‑compliance requiring urgent action.
- Major Findings — Important weaknesses that materially increase risk.
- Minor Findings — Deficiencies with limited impact.
- Observations — Opportunities to improve without immediate risk.
The objective is not finding large numbers of issues but identifying meaningful risks and their causes.
CAPAs
Audit findings typically result in CAPAs. Corrective and Preventive Actions should:
- Address root causes
- Include measurable objectives
- Define owners and timelines
- Include verification criteria
- Be proportionate to the risk
Weak CAPAs address only symptoms; strong CAPAs change processes, behaviours or systems and include verification that objectives are met.
For additional discussion see: [[audit-capas]]
The QPPV Perspective
Audits provide one of the most important sources of assurance available to a QPPV. The QPPV cannot directly observe every pharmacovigilance activity. Audit programmes help provide visibility regarding:
- Compliance
- Governance
- Risks
- System effectiveness
This information supports informed oversight and reporting to senior management and regulators.
For additional discussion see: [[qppv-and-audit-oversight]]
Inspection Perspective
Inspectors frequently evaluate audit programmes. Typical regulator questions include:
- Is the programme risk‑based and aligned to the PSMF?
- Are audits independent from operational teams?
- Are findings addressed in a timely and effective manner?
- Are CAPAs effective and verified with evidence?
- Are repeat issues occurring?
Regulators expect evidence that audit outcomes drive sustainable improvement.
Common Misconceptions
- Audits Exist to Find Fault — Audits exist to provide assurance and support improvement.
- Audits and Inspections Are the Same — They serve different purposes.
- More Findings Mean Better Audits — Finding quality matters more than quantity.
- Audit Closure Equals Improvement — Improvement requires effective CAPAs and verification.
Understanding these distinctions improves audit effectiveness.
Characteristics of Effective Audits
Strong audits typically demonstrate:
- Independence and objectivity
- Risk focus aligned to patient and regulatory risk
- Evidence‑based conclusions
- Practical, measurable recommendations
- Effective, documented follow‑up and verification
These characteristics increase organisational value significantly.
Governance of an Audit Programme
An effective audit programme requires clear governance:
- Sponsorship: Senior management sponsors the programme; QPPV should have direct visibility of audit outcomes.
- Reporting lines: Audit reports should be provided to PV governance forums, senior management and the QPPV. The audit function must have sufficient independence (reporting to Head of Compliance/QA or equivalent).
- Audit charter: A documented charter should define independence, scope, frequency, escalation and confidentiality rules.
- Resourcing: Trained auditors with PV subject‑matter knowledge and audit skills.
- Oversight: An audit steering committee or similar body should review the programme, resource needs and recurring themes.
- Conflict of interest management: Clear rules to prevent auditors from assessing their own work or direct subordinates.
- Record retention: Policies to retain audit records, evidence and CAPA verification records in accordance with regulation and company policy.
Regulatory expectations (e.g., EMA GVP Module IV and ICH Q9) require documented quality systems and internal review processes; audit governance should demonstrate compliance with those principles.
Regulatory Context
Auditing is explicitly addressed in regulatory guidance and legislation:
- EMA GVP Module IV — Pharmacovigilance Audits: sets out expectations for audit frequency, independence, scope and record‑keeping.
- EMA GVP Module I — Pharmacovigilance Systems and Their Quality Systems: emphasises the need for documented quality systems and periodic review.
- ICH Q9 Quality Risk Management: supports risk‑based audit planning and prioritisation.
- National regulations and inspection programmes expect auditable evidence of effective PV systems (Regulation (EC) No 726/2004, Directive 2001/83/EC, Commission Implementing Regulation (EU) No 520/2012).
Audits are frequently inspected during regulatory inspections. Demonstrable alignment of the audit programme with these guidance documents is essential.
Practical Implementation Details
This section provides pragmatic steps and templates to make audits inspection‑ready.
Audit Planning and Timelines
- Strategy: Annual audit plan based on risk assessment and inspection history.
- Timeline examples:
- Planning and scoping: 1–3 weeks
- Preparation (document requests, sampling plan): 1–2 weeks
- Fieldwork: 1–5 business days per scope (varies by complexity)
- Draft report: within 10 business days after fieldwork
- Final report: within 5 business days of receipt of management responses
- CAPA implementation and verification: timelines aligned to risk (critical within 30 days; major within 90 days; minor within 6 months)
- Document request lists should be issued at least 7 business days before fieldwork for complex audits.
Sampling Methodology
- Determine sample size based on population, expected error rate, confidence level and risk.
- Use stratified random sampling for ICSRs (stratify by source, seriousness, country).
- For vendor audits, sample high‑risk contracts and critical processes (e.g., SAE intake, coding, reconciliation).
- Sample re‑review of cases should include closed and recently processed cases.
Evidence Collection and Handling
- Evidence types: system extracts, database reports, email threads, meeting minutes, training records, SOP version logs, change control records, system audit trails, screenshots with timestamps, signed forms.
- Evidence management: assign unique identifiers, maintain an evidence index and store copies in a secure audit file.
- Chain of evidence: record who produced the evidence, extraction method, extraction date and any filters used.
- For electronic evidence, capture metadata (system user, timestamps, export report parameters) and retain original exports.
Interviews and Observations
- Use structured interview guides linked to scope.
- Record interview outcomes in writing; obtain confirmation if factual statements become critical evidence.
- Observe actual processes: case intake, triage meetings, signal review meetings, safety report generation and vendor interactions.
Remote Versus On‑Site Audits
- Remote audits require secure document exchange platforms and controlled screen‑sharing.
- On‑site audits enable observation of physical controls (archives, printed documentation, on‑premise vendor activities).
- Hybrid approaches combine both methods; plan to verify critical items on‑site where possible.
Audit Tools and Checklists
- Maintain standardised checklists mapped to GVP, ICH and local regulations.
- Use electronic audit management tools for scheduling, evidence tracking, finding management and integration with CAPA systems.
Inspection‑Ready Checklist
The following checklist is intended to be used by organisations to prepare for internal audits and regulatory inspections. Items are grouped by area with suggested evidence examples and references to typical regulatory expectations.
Note: Use the checklist as a minimum; adapt to local requirements and organisational context.
Governance and Quality System
- Audit charter and programme (annual plan, risk rationale)
- Evidence: latest audit plan, risk register entry, minutes from audit steering committee
- Regulatory reference: GVP I, GVP IV
- Roles and responsibilities (QPPV, Head of PV, PV governance boards)
- Evidence: organogram, job descriptions, delegation logs
- PSMF (complete and up to date)
- Evidence: current PSMF with approval date, index and distribution list
- Regulatory reference: GVP Module II
- Management review records and quality metrics reporting
- Evidence: management review meeting minutes, KPI dashboards, trending reports
Procedures and Documentation
- SOPs (current versions, change history and distribution list)
- Evidence: SOP index, version history, training records
- Document control and retention
- Evidence: document control policy, archived superseded SOPs
Case Processing and ICSR Management
- ICSR intake, triage and processing procedures
- Evidence: full copy of selected ICSRs, source documents, data entry timestamps, medical review notes
- Timeliness for reporting (E2B transmission logs, gateway reports)
- Evidence: system reports showing receipt and transmission dates, reconciliation logs
- Regulatory reference: ICH E2B, national reporting requirements
- Quality of narratives and case causality assessment
- Evidence: annotated case narratives, medical review comments
Signal Management and Risk Management
- Signal detection, evaluation and documentation procedures
- Evidence: signal logs, signal assessment documents, minutes of signal review meetings
- Regulatory reference: GVP Module IX
- Risk management planning and RMP updates
- Evidence: RMP versions, Risk minimisation measures completion evidence
Aggregate Reporting
- PSUR/DSUR/PBRER processes and approvals
- Evidence: draft and final reports, sign‑off records, distribution logs
- Literature review methodology and results
- Evidence: search strategy, search results, exclusion/inclusion logs
Vendor Oversight
- Contracts, SLAs and delegation of duties
- Evidence: contracts, annexes, defined responsibilities matrix
- Vendor audit records and oversight activities
- Evidence: vendor audit reports, corrective action confirmations, KPI reporting from vendor
IT Systems and Data Integrity
- Safety database configuration and validation documentation (V&V)
- Evidence: validation reports, change control records, incident logs
- Audit trails and user access controls
- Evidence: system audit trail extracts, user access lists, privileged account management records
- Regulatory relevance: data integrity expectations
Training and Competency
- Training matrix and completion evidence for PV staff
- Evidence: training logs, attendance sheets, competency assessments
- Induction and continuous professional development records
CAPA and Continuous Improvement
- CAPA register and status
- Evidence: CAPA tracker extract, evidence of implementation, verification records
- Closure evidence for previous audit findings and inspection observations
- Evidence: closure reports with objective evidence and effectiveness checks
Inspection Readiness
- Previous inspection reports and responses
- Evidence: inspection reports, follow‑up letters, CAPA evidence
- Inspection pack: curated copies of PSMF, SOPs, list of investigators, delegated responsibilities, contact list
Inspection Relevance Mapping
Each checklist item maps to regulatory expectations. Example mappings:
- PSMF completeness ↔ GVP Module II
- Audit programme and independence ↔ GVP Module IV
- Signal management documentation ↔ GVP Module IX
- Data integrity and system validation ↔ national GMP/GDP expectations and EMA guidance
- Vendor oversight ↔ GVP and contractual obligations
During inspection, regulators will routinely request evidence listed above. Having a consolidated, indexed inspection pack accelerates response and reduces risk.
Audit Evidence Examples — Concrete Samples
Regulators and internal reviewers prefer concrete, verifiable evidence. Examples:
- ICSR evidence:
- Export of ICSR from safety database showing unique ID, case creation date, data entry timestamps and user IDs
- Original source (fax/email/electronic form) with extraction metadata
- Medical reviewer signed assessment and causality rationale
- Timeliness evidence:
- Gateway transmission log showing ICSR sent to EudraVigilance with timestamp and transmission report
- SOP change evidence:
- SOP with tracked changes, approval email, version history and training completion list for affected staff
- Vendor evidence:
- Signed contract annex delegating SAE intake, vendor SOPs, recent vendor audit report and vendor CAPA closure evidence (emails and updated SOPs)
- System validation:
- Test scripts, test results, traceability matrix and change control record for production release
- Meeting evidence:
- Signal review minutes with attendees, action items, assigned owners and timestamps; recording or transcript where applicable
- CAPA closure evidence:
- Implemented SOPs, screenshots of system configuration, training records, KPI dashboards showing improved metrics
- Data integrity:
- Database audit trail extract showing record creation, changes and user IDs with unalterable metadata
Templated Audit Report (Inspection‑Ready)
Below is a structured, templated audit report suitable for internal distribution and regulatory review. Populate the template with factual evidence and avoid subjective language. Maintain an evidence index and attach extracts.
Audit Report - Report ID: [AUD‑YYYY‑NNN] - Date: [YYYY‑MM‑DD] - Audit type: [Internal / Vendor / For‑Cause / Follow‑Up] - Audit team: [Lead auditor, co‑auditor(s), technical experts] - Auditee: [Company/Organisation/Department/Vendor] - Scope: [Concise description] - Period audited: [Dates] - Location: [On‑site / Remote / Hybrid] - Compliance references: [GVP modules, ICH, local regulations]
Executive Summary - Objective of the audit - Scope and rationale (risk basis) - Overall conclusion (e.g., "PV system is generally effective with targeted improvement areas" or "Significant deficiencies identified that require immediate corrective action") - Number of findings by grade (Critical: X, Major: Y, Minor: Z, Observations: O) - Immediate actions required (if critical)
Methodology - Documents reviewed (referenced using evidence index identifiers) - Interviews conducted (roles and titles) - Sample selection and rationale (including sample sizes) - Tools used (audit checklists, case re‑review templates, database queries)
Detailed Findings (Table format recommended) - Finding ID: [e.g., F‑2026‑001] - Finding grade: [Critical / Major / Minor / Observation] - Finding title: [Concise statement] - Condition (what was observed) - Criteria (regulatory or internal standard) - Cause (root cause analysis summary) - Effect / Risk (patient safety, regulatory risk) - Evidence (specific items with evidence IDs, dates and excerpts) - Recommended action (concise) - Owner (name, role) - Target completion date - Verification method and criteria (see section below)
Example entry:
Finding ID: F‑2026‑001 - Grade: Major - Title: Delayed E2B transmission for serious ICSRs - Condition: 6 of 20 sampled serious ICSRs were transmitted to the gateway after regulatory timeframes (3–10 days late) - Criteria: ICH E2B / national reporting timelines - Root cause: Manual triage process without defined SLAs and missing automatic gateway reconciliation - Effect: Regulatory reporting delays; potential for inspectional observation - Evidence: ICSR exports (EVID‑ICS‑001 to EVID‑ICS‑006), gateway logs (EVID‑GATE‑001), SOP‑ICSR v1.2 (EVID‑SOP‑002) - Recommended action: Implement automatic gateway reconciliation, update SOPs, retrain intake team - Owner: Head of Safety Operations - Target date: YYYY‑MM‑DD - Verification method: Reconciliation report for next 60 consecutive reports showing 100% on‑time transmission; evidence: reconciliation export (EVID‑VERIFY‑001), training records (EVID‑TRAIN‑010)
Root Cause Analysis - For each finding, include a brief root cause analysis (5‑why, fishbone or similar) and document supporting evidence.
CAPA Plan (for all findings) - CAPA ID: [C‑YYYY‑NNN] - Linked finding(s): [Finding IDs] - Action description: [Detailed, specific actions] - Owner: [Name / role] - Start date: - Target completion date: - Resources required: - SMART success criteria: - Verification method(s): [Documents, system extracts, tests, interviews] - Post‑implementation monitoring: [KPI to be tracked, frequency, threshold for concern]
Example CAPA SMART criteria: - Action: Implement gateway reconciliation automation - Success criterion: 100% automated reconciliation for all safety case transmissions within 30 days of implementation; measured by reconciliation reports for 60 consecutive business days showing zero unreconciled transmissions. - Verification evidence: System configuration change record, test scripts and results, production reconciliation reports, training records.
Follow‑Up and Verification - Date for verification activity - Verifier (authorised QA or independent reviewer) - Verification evidence required (list and evidence IDs) - Decision: Accept CAPA / Require additional actions / Re‑audit
Annexes - Evidence index (unique IDs, description, location) - Audit checklist used (mapping to GVP/ICH) - Interview summaries - Detailed case re‑review notes - CAPA tracker extract - Audit team CVs and independence statements
Use factual wording in the report. Avoid emotive language and ensure each finding is traceable to evidence.
CAPA Verification Criteria — Detailed Guidance
Effective verification converts implemented actions into demonstrable risk reduction. Verification criteria should be measurable, objective and proportionate.
Principles: - Define what success looks like before implementation. - Use multiple evidence types (documents, system extracts, re‑audits). - For process changes, require trend evidence over time, not single‑point snapshots. - For system changes, require testing evidence, validation and operational monitoring.
Verification categories and examples:
- Documented Implementation
- Evidence: updated SOP with version number, approval signature and change control record.
-
Verification criterion: SOP distributed and training completed by all required staff (100% completion, training records EVID‑TRAIN‑XXX).
-
Procedural Compliance
- Evidence: re‑rated process samples, checklists completed as per new SOP.
-
Verification criterion: re‑review of 20 consecutive cases shows adherence in 95% of cases.
-
System Change and Validation
- Evidence: change control, IQ/OQ/PQ or equivalent test scripts and results, production monitoring screenshots.
-
Verification criterion: system change implemented in production, validated, and in daily reconciliation for 60 business days with zero critical errors.
-
Behavioural and Competency Change
- Evidence: attendance and assessment records, competency tests, QC sampling results.
-
Verification criterion: post‑training competency assessment score average ≥ 85% and case re‑review showing improved accuracy.
-
Metric Improvement
- Evidence: KPI dashboards and trend reports.
-
Verification criterion: time to report median reduced from X to Y within Z months; sustained for at least two consecutive quarters.
-
Vendor Remediation
- Evidence: vendor CAPA implementation report, independent re‑audit report, contractual amendment if required.
-
Verification criterion: vendor re‑audit results show closure of previously noted major findings; performance KPIs meet SLA for three months.
-
Root Cause Elimination
- Evidence: documentation showing systemic changes (process maps, new controls, monitoring).
- Verification criterion: no recurrence of the finding in a defined observation window (e.g., six months) validated by sampling and monitoring.
Decision rules for CAPA closure: - Accept CAPA closed: All verification criteria met and evidence retained in audit/CAPA file. - Require further action: Partial evidence or insufficient trend support; define additional steps. - Re‑audit required: For critical findings or where verification cannot be robustly demonstrated remotely.
Document closure decisions with verifier sign‑off, date and evidence index.
Practical Examples of CAPA Verification Evidence
- Example 1 (timeliness): Reconciliation report (EVID‑RECON‑001) shows 120 consecutive ICSRs transmitted within regulatory timelines; comparator pre‑CAPE report shows previous 20% lateness.
- Example 2 (system validation): Change control CC‑2026‑045, test scripts TS‑2026‑045, PQ results PQ‑2026‑045 and production monitoring report PM‑2026‑045 showing zero exceptions for 90 days.
- Example 3 (training): Training module completion records with electronic sign‑off and competency quiz results for the cohort (EVID‑TRAIN‑2026‑01).
- Example 4 (vendor): Re‑audit report VEND‑AUD‑2026‑02 with closed findings, vendor SOPs updated and signed, performance dashboard for three months showing SLA compliance.
Audit Follow‑Up and Trending
Audits generate information for continuous improvement. Key elements:
- CAPA tracker with status, owners, target dates and verification evidence links.
- Trending of audit findings by theme (e.g., data integrity, timeliness, vendor oversight) to identify systemic issues.
- Management reporting: quarterly audit programme report to governance, highlighting recurring themes and resource needs.
- Re‑audit triggers: major or critical findings should trigger either focused re‑audit or inclusion in annual plan.
Inspection Relevance — What Inspectors Look For
During inspections, regulators will often assess:
- Existence of a risk‑based audit programme aligned to PSMF and GVP.
- Independence of auditors and documentation of independence checks.
- Evidence that findings result in effective CAPAs with verifiable evidence.
- Trending and recurring issues: are problems addressed systemically?
- Documentation practices and evidence management.
- Adequacy of vendor oversight, including audit results and CAPA closures.
- Data integrity and validated IT controls.
- QPPV involvement and visibility of audit outcomes.
Providing an inspection‑ready audit file — with a clear evidence index, report, CAPA tracker and verification evidence — reduces inspection risk and demonstrates control.
Key Takeaways
- Pharmacovigilance audits provide independent assurance regarding system effectiveness and regulatory compliance.
- Audit programmes should be risk‑based, evidence‑driven and governed with clear independence.
- Effective audits produce actionable findings, SMART CAPAs and measurable verification criteria.
- Prepare inspection‑ready audit files: structured reports, evidence indices and concrete verification evidence.
- Demonstrable closure and verification of CAPAs is essential to satisfy regulators and protect patients.
- Mature organisations use audits strategically for governance, continuous improvement and inspection preparedness.
References
- EMA Good Pharmacovigilance Practices (GVP) Module IV – Pharmacovigilance Audits.
- EMA Good Pharmacovigilance Practices (GVP) Module I – Pharmacovigilance Systems and Their Quality Systems.
- EMA Good Pharmacovigilance Practices (GVP) Module III – Pharmacovigilance Inspections.
- Regulation (EC) No 726/2004.
- Directive 2001/83/EC.
- Commission Implementing Regulation (EU) No 520/2012.
- ICH Q9 Quality Risk Management.
- ICH E2E Pharmacovigilance Planning.