01
Safety governance & benefit-risk
How safety decisions are made: accountability, qualified medical review, decision forums, benefit-risk judgement, escalation and the explicit acceptance of residual risk.
Benefit-risk is a judgement that changes as evidence accumulates, and it must be made by people qualified and empowered to reach an uncomfortable conclusion. Where safety governance reports into commercial ownership, the structure itself is a finding.
HOW IT FAILS
- Benefit-risk is revisited only when a regulator asks, rather than when the evidence changes.
- The qualified person for pharmacovigilance holds the title without the authority or the information to act.
- Decisions are recorded as outcomes with no record of the alternatives considered or the reasoning.
WHAT CONTAINS IT
- Defined triggers that oblige benefit-risk re-evaluation, independent of external request.
- Safety authority positioned so a decision can be taken against commercial interest.
- Decision records capturing options, evidence, dissent and rationale, not only conclusions.
EVIDENCE IT OPERATES
- Safety governance terms of reference and decision records.
- Benefit-risk evaluations with triggers and evidence.
- Qualified person appointment, responsibilities and escalation records.
02
Adverse-event & case management
Individual case handling end to end: intake from every source, validity, seriousness and expectedness, causality, coding, follow-up, quality control and regulatory reporting within the clock.
Case processing carries statutory timelines counted from the day anyone in the organisation first became aware. That clock is why a report sitting in a sales representative’s inbox is already a compliance failure before pharmacovigilance has heard of it.
HOW IT FAILS
- Day-zero is taken as receipt by the safety department rather than first awareness anywhere in the organisation.
- Follow-up is attempted once and abandoned, leaving cases permanently incomplete and unassessable.
- Coding is applied inconsistently, so the same event under two terms never aggregates into a signal.
WHAT CONTAINS IT
- Awareness-based day-zero applied across every function that may receive a report, with training to match.
- Structured follow-up with defined attempts and documented outcome.
- Coding conventions with quality review, so aggregation is not defeated by terminology.
EVIDENCE IT OPERATES
- Case records with day-zero determination and submission timeliness.
- Follow-up attempts, their timing and documented outcome.
- Coding quality review records and compliance metrics.
03
Signal detection & management
Finding what the individual cases do not show: data sources, detection methods, validation, prioritisation, assessment, resulting recommendations and tracking to closure.
Signals emerge from patterns rather than from single cases, and the value is in early detection. A validated signal that takes a year to reach a labelling change has been detected but not acted on.
HOW IT FAILS
- Detection runs only on the internal safety database, ignoring literature, registries and regulator databases.
- Signals are validated and then queue without prioritisation, so the significant one waits behind the trivial.
- Closure is recorded when assessment finishes rather than when the resulting action is implemented.
WHAT CONTAINS IT
- Detection across internal, literature, regulatory and real-world sources with defined periodicity.
- Prioritisation by potential patient impact, with timelines attached to each priority.
- Signal closure defined as implemented action, tracked through to labelling or risk-minimisation change.
EVIDENCE IT OPERATES
- Signal detection runs with sources and methods.
- Signal register with validation, prioritisation and status.
- Closure records linking assessment to implemented action.
04
Aggregate and periodic safety reporting
Periodic safety reporting: the reports themselves, cumulative analyses, reporting intervals and data lock points, medical conclusions and submission to each authority that requires them.
Aggregate reports are where the cumulative picture is assembled and where a regulator sees whether the organisation is drawing the right conclusion from its own data. A technically complete report that reaches a defensive conclusion is worse than a late one.
HOW IT FAILS
- Intervals and data lock points are tracked per report rather than per product across markets, so one submission is missed.
- The report compiles data without a medical conclusion that engages with what the data suggest.
- Content is reused between periods, so a change in the cumulative picture is not reflected in the narrative.
WHAT CONTAINS IT
- A single schedule of reporting obligations per product and market with owners and lead times.
- Medical review that draws and records a conclusion, including where it differs from the previous period.
- Cumulative analysis genuinely refreshed each period rather than carried forward.
EVIDENCE IT OPERATES
- Reporting obligation schedule with submission confirmations.
- Reports with documented medical review and conclusions.
- Cumulative analyses showing period-on-period change.
05
Risk-management plans & minimization
The plan for known and potential risks: safety concerns, routine and additional minimisation measures, effectiveness evaluation, educational materials and commitments made to authorities.
Risk minimisation is a commitment with an effectiveness obligation attached. Distributing an educational pack is an activity; showing that prescribing behaviour changed is the requirement, and the two are routinely confused.
HOW IT FAILS
- Effectiveness is measured by distribution volume rather than by whether behaviour or outcomes changed.
- Additional measures accumulate across markets with no assessment of whether the earlier ones worked.
- Commitments are tracked by regulatory affairs while implementation sits elsewhere, and the two diverge.
WHAT CONTAINS IT
- Effectiveness indicators defined when the measure is proposed, with a method capable of detecting change.
- Periodic review of whether existing measures are working before adding more.
- A single commitment register spanning regulatory obligation and operational implementation.
EVIDENCE IT OPERATES
- Risk management plans with safety concerns and measures.
- Effectiveness evaluation results and resulting changes.
- Commitment register with implementation evidence.
06
Complaints, device vigilance & product surveillance
Product complaints and device vigilance: intake, reportability assessment, investigation, regulatory vigilance reporting, trending and the interfaces to quality and manufacturing.
A complaint is simultaneously a quality signal and potentially a reportable safety event, and the two assessments run on different clocks. Where intake is single-threaded through quality, the vigilance timeline can expire during the technical investigation.
HOW IT FAILS
- Reportability is assessed after the technical investigation concludes, by which time the reporting clock has run.
- Complaints are trended by product and not by failure mode, so a recurring mechanism across products is invisible.
- Complaints closed as "no fault found" are not trended, discarding the pattern they collectively form.
WHAT CONTAINS IT
- Reportability assessed on intake, in parallel with and not after the technical investigation.
- Trending by failure mode and mechanism as well as by product.
- No-fault-found complaints trended explicitly, with a threshold that triggers deeper investigation.
EVIDENCE IT OPERATES
- Complaint records with intake, reportability decision and investigation.
- Vigilance and MDR submissions with timeliness metrics.
- Trending across failure modes including no-fault-found outcomes.
07
Postauthorization studies & real-world evidence
Evidence generated after authorisation: post-authorisation safety studies, post-market clinical follow-up, registries, observational evidence, protocols, data fitness and reporting.
Postmarket studies answer questions the trials could not, and they are frequently conditions of approval. Their weakness is data fitness — real-world data were collected for another purpose, and whether they can support the question is a judgement that must be made explicitly.
HOW IT FAILS
- A real-world data source is adopted for its size without assessing whether it captures the outcome of interest.
- Study commitments are tracked as regulatory milestones with no oversight of feasibility until recruitment fails.
- Results are reported to the authority and never routed into benefit-risk or labelling review.
WHAT CONTAINS IT
- Data fitness assessed against the specific question before a source is selected.
- Feasibility monitored during conduct with early escalation when a commitment is at risk.
- Results routed into safety governance and labelling review as a defined step.
EVIDENCE IT OPERATES
- Study protocols with data-source fitness assessment.
- Commitment tracking with feasibility and progress reporting.
- Study reports and the benefit-risk or labelling decisions taken from them.
08
Recalls, field actions & safety communications
Acting on product already distributed: health-hazard evaluation, scope determination, coordination with authorities, execution, effectiveness checks and closure.
A field action is the point where every other system is tested at once — traceability determines the scope, distribution records determine reach, and the effectiveness check determines whether the product actually came back. Weakness anywhere widens the action.
HOW IT FAILS
- Scope is set by batch genealogy that proves incomplete, so the action is expanded mid-execution.
- Effectiveness is measured by notification sent rather than by product recovered or corrected.
- Root cause is closed before the action completes, so recurrence risk is judged on partial information.
WHAT CONTAINS IT
- Health-hazard evaluation and scope determination by a defined multidisciplinary decision, documented.
- Effectiveness measured by response and recovery rate with escalation for non-responders.
- Root-cause completion tracked separately from action closure, both to defined criteria.
EVIDENCE IT OPERATES
- Health-hazard evaluations and scope decisions with rationale.
- Distribution and traceability records supporting scope.
- Effectiveness check results and closure records including root cause.
09
Medical information & product inquiry intelligence
Handling enquiries about the product: scientific responses, enquiry management, escalation of anything that is actually a safety report, trend signals, content control and interfaces to safety and quality.
Medical information is a high-volume front door through which adverse events and complaints arrive disguised as questions. It is also where the enquiry pattern itself is a signal — a spike in questions about administration often precedes reported use errors.
HOW IT FAILS
- Enquiry handlers screen for explicit adverse-event language and miss reports embedded in a clinical question.
- Standard response content ages out of alignment with the current approved labelling.
- Enquiry trends are reported as volume metrics with no clinical review for emerging themes.
WHAT CONTAINS IT
- Screening criteria and training aimed at recognising an event described indirectly.
- Response content version-controlled against current labelling with a defined review cycle.
- Clinical review of enquiry themes, routed to signal management where a pattern emerges.
EVIDENCE IT OPERATES
- Enquiry records with adverse-event and complaint screening outcomes.
- Response content library with version control and labelling alignment.
- Enquiry trend analyses and referrals into signal management.
10
Safety systems, vendors & partner exchange
The infrastructure behind safety: databases, dictionaries, interfaces, partner agreements, reconciliation, timeline management, vendor oversight and the evidence an inspector will ask for.
Safety data arrive from partners, vendors and affiliates, and every exchange is a place where a case can be delayed or lost. Reconciliation is the control that finds those losses, and it only works if it is periodic and two-way.
HOW IT FAILS
- Reconciliation with partners is annual, so a case lost in transfer is discovered long after its reporting clock expired.
- Dictionary versions differ between partners, so the same event codes differently on each side.
- Safety data exchange agreements exist with commercial partners but not with distributors and licensees who also receive reports.
WHAT CONTAINS IT
- Periodic two-way reconciliation at a frequency short enough to protect reporting timelines.
- Dictionary version alignment agreed and verified across every exchanging party.
- Safety data exchange agreements covering every party that may receive a report, including distributors.
EVIDENCE IT OPERATES
- Reconciliation records with discrepancies and resolution.
- Dictionary version control and upgrade records.
- Safety data exchange agreements and partner oversight records.