What is a Pharmacovigilance Audit?

A foundational guide to pharmacovigilance audits, audit principles, audit lifecycle, independence and regulatory expectations.

Audio Lesson 11 min

What is a Pharmacovigilance Audit?

Introduction

Pharmacovigilance systems are built upon trust.

Regulators trust that Marketing Authorisation Holders have established effective systems to:

However, trust alone is insufficient.

Organisations must periodically verify that their systems are functioning as intended. This is the role of pharmacovigilance auditing.

A pharmacovigilance audit provides independent assessment of whether the pharmacovigilance system is operating effectively and whether risks are being managed appropriately.

What Is a Pharmacovigilance Audit?

A pharmacovigilance audit is a systematic, independent and documented assessment of pharmacovigilance activities. The objective is to determine whether:

Audits evaluate both:

Compliance

Are requirements being met?

Effectiveness

Are controls actually working?

This distinction is important. A process may be compliant on paper while remaining ineffective in practice.

Key Characteristics of Audits

Several characteristics distinguish audits from routine operational activities.

Systematic

Audits follow a defined methodology. Activities are planned and documented.

Independent

Auditors maintain objectivity. They should not assess their own work.

Evidence‑Based

Conclusions are supported by verifiable evidence rather than assumptions.

Risk‑Focused

Attention is directed toward areas creating the greatest risk.

These principles support credibility and consistency.

Why Pharmacovigilance Audits Exist

All systems contain risk.

Even well‑managed organisations may experience:

Audits help identify these issues before they become:

A useful way to view audits is:

Audits provide assurance that controls continue to operate effectively.

Audits Versus Inspections

Although both audits and inspections assess pharmacovigilance systems, their purpose differs.

Audit Inspection
Conducted by or on behalf of the organisation Conducted by regulators
Focuses on assurance and improvement Focuses on regulatory compliance
Part of internal governance Part of regulatory oversight
Continuous activity Periodic regulatory activity

A strong audit programme improves inspection readiness. However, audits should not exist solely to prepare for inspections.

Audits Versus Monitoring

Audits and monitoring are different activities.

Monitoring

Usually focuses on ongoing operational performance. Examples:

Auditing

Provides independent assessment of system effectiveness.

Monitoring asks:

What is happening?

Auditing asks:

Why is it happening and are controls effective?

Both activities are important and complementary.

The Purpose of Auditing

Audits provide assurance, inform management and guide improvement. Audits help answer:

The strongest audit programmes support organisational learning rather than simply generating findings.

The Audit Lifecycle

Most pharmacovigilance audits follow a structured lifecycle.

Planning

Define objectives, scope, risk rationale, resource needs, audit team composition, timeline and reporting lines. Establish independence and conflict‑of‑interest checks.

Preparation

Assemble background documentation (PSMF, SOPs, previous audit and inspection reports, CAPA logs, KPI trends), create the document request list and sampling plan, and prepare checklists and interview guides.

Fieldwork

Collect and evaluate evidence: interviews, document review, system extracts, case re‑reviews, observation of processes and meetings. Record evidence with unique identifiers and retain original extracts/screenshots.

Reporting

Document factual observations, risk evaluation, root cause analysis, and recommended CAPAs. Provide graded findings (critical/major/minor/observation) and an executive summary for senior management.

CAPAs

Agree corrective and preventive actions with owners, including SMART objectives, resources and timelines.

Follow‑Up

Verify implementation and effectiveness of CAPAs with evidence and metrics. Determine whether re‑audit or monitoring is required.

Each stage contributes to audit quality and inspection readiness.

Audit Scope

Audit scope varies according to objectives. Common scopes include:

Scope selection should be risk‑based, dynamic and documented.

Risk-Based Auditing

Modern audit programmes increasingly use risk‑based approaches. This recognises that not all activities create equal risk. Factors commonly considered include:

Higher‑risk activities receive greater audit attention and more rigorous sampling.

For additional discussion see: [[risk-based-audit-planning]]

Audit Findings

Audit findings identify weaknesses, risks or opportunities for improvement.

Common categories include:

The objective is not finding large numbers of issues but identifying meaningful risks and their causes.

CAPAs

Audit findings typically result in CAPAs. Corrective and Preventive Actions should:

Weak CAPAs address only symptoms; strong CAPAs change processes, behaviours or systems and include verification that objectives are met.

For additional discussion see: [[audit-capas]]

The QPPV Perspective

Audits provide one of the most important sources of assurance available to a QPPV. The QPPV cannot directly observe every pharmacovigilance activity. Audit programmes help provide visibility regarding:

This information supports informed oversight and reporting to senior management and regulators.

For additional discussion see: [[qppv-and-audit-oversight]]

Inspection Perspective

Inspectors frequently evaluate audit programmes. Typical regulator questions include:

Regulators expect evidence that audit outcomes drive sustainable improvement.

Common Misconceptions

Understanding these distinctions improves audit effectiveness.

Characteristics of Effective Audits

Strong audits typically demonstrate:

These characteristics increase organisational value significantly.

Governance of an Audit Programme

An effective audit programme requires clear governance:

Regulatory expectations (e.g., EMA GVP Module IV and ICH Q9) require documented quality systems and internal review processes; audit governance should demonstrate compliance with those principles.

Regulatory Context

Auditing is explicitly addressed in regulatory guidance and legislation:

Audits are frequently inspected during regulatory inspections. Demonstrable alignment of the audit programme with these guidance documents is essential.

Practical Implementation Details

This section provides pragmatic steps and templates to make audits inspection‑ready.

Audit Planning and Timelines

Sampling Methodology

Evidence Collection and Handling

Interviews and Observations

Remote Versus On‑Site Audits

Audit Tools and Checklists

Inspection‑Ready Checklist

The following checklist is intended to be used by organisations to prepare for internal audits and regulatory inspections. Items are grouped by area with suggested evidence examples and references to typical regulatory expectations.

Note: Use the checklist as a minimum; adapt to local requirements and organisational context.

Governance and Quality System

Procedures and Documentation

Case Processing and ICSR Management

Signal Management and Risk Management

Aggregate Reporting

Vendor Oversight

IT Systems and Data Integrity

Training and Competency

CAPA and Continuous Improvement

Inspection Readiness

Inspection Relevance Mapping

Each checklist item maps to regulatory expectations. Example mappings:

During inspection, regulators will routinely request evidence listed above. Having a consolidated, indexed inspection pack accelerates response and reduces risk.

Audit Evidence Examples — Concrete Samples

Regulators and internal reviewers prefer concrete, verifiable evidence. Examples:

Templated Audit Report (Inspection‑Ready)

Below is a structured, templated audit report suitable for internal distribution and regulatory review. Populate the template with factual evidence and avoid subjective language. Maintain an evidence index and attach extracts.


Audit Report - Report ID: [AUD‑YYYY‑NNN] - Date: [YYYY‑MM‑DD] - Audit type: [Internal / Vendor / For‑Cause / Follow‑Up] - Audit team: [Lead auditor, co‑auditor(s), technical experts] - Auditee: [Company/Organisation/Department/Vendor] - Scope: [Concise description] - Period audited: [Dates] - Location: [On‑site / Remote / Hybrid] - Compliance references: [GVP modules, ICH, local regulations]

Executive Summary - Objective of the audit - Scope and rationale (risk basis) - Overall conclusion (e.g., "PV system is generally effective with targeted improvement areas" or "Significant deficiencies identified that require immediate corrective action") - Number of findings by grade (Critical: X, Major: Y, Minor: Z, Observations: O) - Immediate actions required (if critical)

Methodology - Documents reviewed (referenced using evidence index identifiers) - Interviews conducted (roles and titles) - Sample selection and rationale (including sample sizes) - Tools used (audit checklists, case re‑review templates, database queries)

Detailed Findings (Table format recommended) - Finding ID: [e.g., F‑2026‑001] - Finding grade: [Critical / Major / Minor / Observation] - Finding title: [Concise statement] - Condition (what was observed) - Criteria (regulatory or internal standard) - Cause (root cause analysis summary) - Effect / Risk (patient safety, regulatory risk) - Evidence (specific items with evidence IDs, dates and excerpts) - Recommended action (concise) - Owner (name, role) - Target completion date - Verification method and criteria (see section below)

Example entry:

Finding ID: F‑2026‑001 - Grade: Major - Title: Delayed E2B transmission for serious ICSRs - Condition: 6 of 20 sampled serious ICSRs were transmitted to the gateway after regulatory timeframes (3–10 days late) - Criteria: ICH E2B / national reporting timelines - Root cause: Manual triage process without defined SLAs and missing automatic gateway reconciliation - Effect: Regulatory reporting delays; potential for inspectional observation - Evidence: ICSR exports (EVID‑ICS‑001 to EVID‑ICS‑006), gateway logs (EVID‑GATE‑001), SOP‑ICSR v1.2 (EVID‑SOP‑002) - Recommended action: Implement automatic gateway reconciliation, update SOPs, retrain intake team - Owner: Head of Safety Operations - Target date: YYYY‑MM‑DD - Verification method: Reconciliation report for next 60 consecutive reports showing 100% on‑time transmission; evidence: reconciliation export (EVID‑VERIFY‑001), training records (EVID‑TRAIN‑010)

Root Cause Analysis - For each finding, include a brief root cause analysis (5‑why, fishbone or similar) and document supporting evidence.

CAPA Plan (for all findings) - CAPA ID: [C‑YYYY‑NNN] - Linked finding(s): [Finding IDs] - Action description: [Detailed, specific actions] - Owner: [Name / role] - Start date: - Target completion date: - Resources required: - SMART success criteria: - Verification method(s): [Documents, system extracts, tests, interviews] - Post‑implementation monitoring: [KPI to be tracked, frequency, threshold for concern]

Example CAPA SMART criteria: - Action: Implement gateway reconciliation automation - Success criterion: 100% automated reconciliation for all safety case transmissions within 30 days of implementation; measured by reconciliation reports for 60 consecutive business days showing zero unreconciled transmissions. - Verification evidence: System configuration change record, test scripts and results, production reconciliation reports, training records.

Follow‑Up and Verification - Date for verification activity - Verifier (authorised QA or independent reviewer) - Verification evidence required (list and evidence IDs) - Decision: Accept CAPA / Require additional actions / Re‑audit

Annexes - Evidence index (unique IDs, description, location) - Audit checklist used (mapping to GVP/ICH) - Interview summaries - Detailed case re‑review notes - CAPA tracker extract - Audit team CVs and independence statements


Use factual wording in the report. Avoid emotive language and ensure each finding is traceable to evidence.

CAPA Verification Criteria — Detailed Guidance

Effective verification converts implemented actions into demonstrable risk reduction. Verification criteria should be measurable, objective and proportionate.

Principles: - Define what success looks like before implementation. - Use multiple evidence types (documents, system extracts, re‑audits). - For process changes, require trend evidence over time, not single‑point snapshots. - For system changes, require testing evidence, validation and operational monitoring.

Verification categories and examples:

  1. Documented Implementation
  2. Evidence: updated SOP with version number, approval signature and change control record.
  3. Verification criterion: SOP distributed and training completed by all required staff (100% completion, training records EVID‑TRAIN‑XXX).

  4. Procedural Compliance

  5. Evidence: re‑rated process samples, checklists completed as per new SOP.
  6. Verification criterion: re‑review of 20 consecutive cases shows adherence in 95% of cases.

  7. System Change and Validation

  8. Evidence: change control, IQ/OQ/PQ or equivalent test scripts and results, production monitoring screenshots.
  9. Verification criterion: system change implemented in production, validated, and in daily reconciliation for 60 business days with zero critical errors.

  10. Behavioural and Competency Change

  11. Evidence: attendance and assessment records, competency tests, QC sampling results.
  12. Verification criterion: post‑training competency assessment score average ≥ 85% and case re‑review showing improved accuracy.

  13. Metric Improvement

  14. Evidence: KPI dashboards and trend reports.
  15. Verification criterion: time to report median reduced from X to Y within Z months; sustained for at least two consecutive quarters.

  16. Vendor Remediation

  17. Evidence: vendor CAPA implementation report, independent re‑audit report, contractual amendment if required.
  18. Verification criterion: vendor re‑audit results show closure of previously noted major findings; performance KPIs meet SLA for three months.

  19. Root Cause Elimination

  20. Evidence: documentation showing systemic changes (process maps, new controls, monitoring).
  21. Verification criterion: no recurrence of the finding in a defined observation window (e.g., six months) validated by sampling and monitoring.

Decision rules for CAPA closure: - Accept CAPA closed: All verification criteria met and evidence retained in audit/CAPA file. - Require further action: Partial evidence or insufficient trend support; define additional steps. - Re‑audit required: For critical findings or where verification cannot be robustly demonstrated remotely.

Document closure decisions with verifier sign‑off, date and evidence index.

Practical Examples of CAPA Verification Evidence

Audits generate information for continuous improvement. Key elements:

Inspection Relevance — What Inspectors Look For

During inspections, regulators will often assess:

Providing an inspection‑ready audit file — with a clear evidence index, report, CAPA tracker and verification evidence — reduces inspection risk and demonstrates control.

Key Takeaways

References

  1. EMA Good Pharmacovigilance Practices (GVP) Module IV – Pharmacovigilance Audits.
  2. EMA Good Pharmacovigilance Practices (GVP) Module I – Pharmacovigilance Systems and Their Quality Systems.
  3. EMA Good Pharmacovigilance Practices (GVP) Module III – Pharmacovigilance Inspections.
  4. Regulation (EC) No 726/2004.
  5. Directive 2001/83/EC.
  6. Commission Implementing Regulation (EU) No 520/2012.
  7. ICH Q9 Quality Risk Management.
  8. ICH E2E Pharmacovigilance Planning.

Last reviewed: 2026-06-11