[ ENTERPRISE PILLAR 13 ]

Safety, Surveillance & Postmarket

Detect, evaluate, communicate, and control product safety and performance signals across the marketed lifecycle.

What this pillar does not claim

This pillar owns product safety and postmarket learning; clinical operations owns trial execution and manufacturing owns product-quality investigations.

The capability framing below, its failure modes and the boundary with neighbouring pillars are SPEQ’s practitioner reading — not a regulatory requirement, and not an assessment of any organization.

THE CAPABILITY

What this capability is

This is the only capability that learns about the product from the world rather than from the organization. Everything else studies it under conditions somebody designed — a protocol, a specification, a qualified process, a validated method. This one studies it under conditions nobody designed: real patients and real users, alongside other treatments, outside the population that was studied, sometimes used in ways the label never contemplated, over durations no trial could afford. Case handling, signal work, periodic review, risk minimisation, complaint handling and field action are one capability because they are one argument examined at four resolutions — is the balance between benefit and harm still what the organization said it was, and if it has moved, what has to change and who has to be told.

Why it is hard

The capability has to reason about a population it cannot see, from a sample it does not control. A report exists because somebody decided to make one, and that decision responds to publicity, to a competitor's news, to how long the product has been marketed and to whether a law firm has been advertising — so a rise in reports is at least as likely to be a change in reporting behaviour as a change in the product, and the denominator that would settle the question does not exist. Nothing inside the branches repairs that: immaculate case processing produces an immaculate record of a biased sample. The second difficulty is that the two available errors are punished asymmetrically. Acting on something that turns out to be noise is immediate, visible and expensive; failing to act on something real is invisible for years and then obvious to everybody in hindsight, which pushes judgement in exactly the direction the evidence is least able to support. And the clock that governs most of the work starts outside the function altogether, on the day anyone anywhere in the organization first hears something — a sales conversation, a market-research transcript, a comment under a post, a call to a switchboard — so timeliness is largely determined by the conduct of people who have never worked in it.

How it fails

Each of these happens with the individual branches below being run competently. That is what makes them capability failures rather than performance problems.

The clock starts where nobody is looking

Awareness begins at first contact with anyone employed by or acting for the organization, not at arrival in the safety system. The commercial team, the medical information line, a market-research vendor and a social media agency are all points of first receipt, and the days lost between their hearing it and the case being entered are days already spent. The function that will be measured on the timeline has no operational control over most of the places it starts.

The complaint that was also an adverse event, filed as one thing

A single report arrives describing both a product defect and something that happened to a person. It enters one intake, gets one classification, and is routed to one process — usually the one whose form it arrived on. The other obligation is not refused; it is simply never raised, and the discovery normally comes months later when somebody reconciles two systems that were never designed to be reconciled.

The signal that was detected, assessed, and never converted

Detection works. Validation works. The assessment concludes that the information for prescribers should change. It then becomes a proposal that enters a queue behind other proposals, is bundled into a future submission for efficiency, and waits. Every step is documented and defensible, and for the eighteen months this takes, nothing whatsoever has changed for the person actually making the treatment decision.

Risk minimisation measured by distribution rather than by effect

The educational materials were produced, approved and sent, and the metric records how many went out. Whether prescribing actually changed, whether the training was completed by the people who needed it, whether the monitoring it asked for is being done — those are harder to measure, so the measure that exists is the one about delivery. The measure of effect is the whole reason the commitment was made.

WHERE THIS STOPS

Ours or theirs

Trial conduct belongs to clinical operations — sites, monitoring, protocol compliance — while the individual safety case arising in a trial belongs here, which makes the reconciliation between the clinical database and the safety database a standing shared obligation rather than either side's chore. Investigating why a batch failed belongs to manufacturing and quality; this capability owns what the product did to a person and what that means for the risk position. The wording of an authorised label and the negotiation with an authority belong to regulatory affairs, once the medical conclusion has been reached here. The argument that recurs is the report that is unmistakably both: a device that malfunctioned and a patient who was harmed, or a quality defect discovered because somebody had a reaction. Two obligations, two clocks, two owners, one piece of paper. The organizations that handle it well do not resolve it by deciding which one it really is; they let it be both from intake, and accept the duplication that entails, because the alternative is a coin toss made by whoever opened the envelope.

Questions practitioners ask

Is a product complaint an adverse event?

Sometimes, and the pair overlap without either containing the other. A complaint about a broken seal with no patient involvement is not an adverse event; a serious reaction with no defect is not a complaint; a device that failed and injured its user is both, and owes both processes. The failure worth designing against is not misclassification in itself but an intake that permits only one answer.

Why does an increase in reports not necessarily mean the product has become less safe?

Because reporting is a behaviour, not a measurement. Attention raises it: a publication, a regulator statement, a lawyer advertising, or simply more people taking the product this year than last. Without a reliable denominator, a count on its own cannot separate a real change in the product from a change in who is bothering to report. That is why signal work asks what else moved before it asks what the numbers mean.

What is the difference between a case and a signal?

A case is one individual experience recorded and assessed on its own terms; causality in any single case is usually undeterminable. A signal is a proposition about the product — that a particular harm may be associated with it — assembled from cases, literature, studies and comparison. Excellent case handling is a prerequisite for signal work and is not the same activity, which is why organizations can be flawless at one and weak at the other.

Where does this pillar stop and clinical development start?

Clinical development owns the studies: their design, their conduct and the evidence they generate. This capability owns the safety view that runs continuously across and beyond them, including during a trial. The practical seam is the study safety report, which is written from clinical data by people who report here, and the reconciliation of the two databases, which nobody enjoys and which is the single most common finding when it is left to whoever has capacity.

CAPABILITY BRANCH MAP

What this pillar contains

01

Safety governance & benefit-risk

How safety decisions are made: accountability, qualified medical review, decision forums, benefit-risk judgement, escalation and the explicit acceptance of residual risk.

Benefit-risk is a judgement that changes as evidence accumulates, and it must be made by people qualified and empowered to reach an uncomfortable conclusion. Where safety governance reports into commercial ownership, the structure itself is a finding.

HOW IT FAILS

  • Benefit-risk is revisited only when a regulator asks, rather than when the evidence changes.
  • The qualified person for pharmacovigilance holds the title without the authority or the information to act.
  • Decisions are recorded as outcomes with no record of the alternatives considered or the reasoning.

WHAT CONTAINS IT

  • Defined triggers that oblige benefit-risk re-evaluation, independent of external request.
  • Safety authority positioned so a decision can be taken against commercial interest.
  • Decision records capturing options, evidence, dissent and rationale, not only conclusions.

EVIDENCE IT OPERATES

  • Safety governance terms of reference and decision records.
  • Benefit-risk evaluations with triggers and evidence.
  • Qualified person appointment, responsibilities and escalation records.
02

Adverse-event & case management

Individual case handling end to end: intake from every source, validity, seriousness and expectedness, causality, coding, follow-up, quality control and regulatory reporting within the clock.

Case processing carries statutory timelines counted from the day anyone in the organisation first became aware. That clock is why a report sitting in a sales representative’s inbox is already a compliance failure before pharmacovigilance has heard of it.

HOW IT FAILS

  • Day-zero is taken as receipt by the safety department rather than first awareness anywhere in the organisation.
  • Follow-up is attempted once and abandoned, leaving cases permanently incomplete and unassessable.
  • Coding is applied inconsistently, so the same event under two terms never aggregates into a signal.

WHAT CONTAINS IT

  • Awareness-based day-zero applied across every function that may receive a report, with training to match.
  • Structured follow-up with defined attempts and documented outcome.
  • Coding conventions with quality review, so aggregation is not defeated by terminology.

EVIDENCE IT OPERATES

  • Case records with day-zero determination and submission timeliness.
  • Follow-up attempts, their timing and documented outcome.
  • Coding quality review records and compliance metrics.
03

Signal detection & management

Finding what the individual cases do not show: data sources, detection methods, validation, prioritisation, assessment, resulting recommendations and tracking to closure.

Signals emerge from patterns rather than from single cases, and the value is in early detection. A validated signal that takes a year to reach a labelling change has been detected but not acted on.

HOW IT FAILS

  • Detection runs only on the internal safety database, ignoring literature, registries and regulator databases.
  • Signals are validated and then queue without prioritisation, so the significant one waits behind the trivial.
  • Closure is recorded when assessment finishes rather than when the resulting action is implemented.

WHAT CONTAINS IT

  • Detection across internal, literature, regulatory and real-world sources with defined periodicity.
  • Prioritisation by potential patient impact, with timelines attached to each priority.
  • Signal closure defined as implemented action, tracked through to labelling or risk-minimisation change.

EVIDENCE IT OPERATES

  • Signal detection runs with sources and methods.
  • Signal register with validation, prioritisation and status.
  • Closure records linking assessment to implemented action.
04

Aggregate and periodic safety reporting

Periodic safety reporting: the reports themselves, cumulative analyses, reporting intervals and data lock points, medical conclusions and submission to each authority that requires them.

Aggregate reports are where the cumulative picture is assembled and where a regulator sees whether the organisation is drawing the right conclusion from its own data. A technically complete report that reaches a defensive conclusion is worse than a late one.

HOW IT FAILS

  • Intervals and data lock points are tracked per report rather than per product across markets, so one submission is missed.
  • The report compiles data without a medical conclusion that engages with what the data suggest.
  • Content is reused between periods, so a change in the cumulative picture is not reflected in the narrative.

WHAT CONTAINS IT

  • A single schedule of reporting obligations per product and market with owners and lead times.
  • Medical review that draws and records a conclusion, including where it differs from the previous period.
  • Cumulative analysis genuinely refreshed each period rather than carried forward.

EVIDENCE IT OPERATES

  • Reporting obligation schedule with submission confirmations.
  • Reports with documented medical review and conclusions.
  • Cumulative analyses showing period-on-period change.
05

Risk-management plans & minimization

The plan for known and potential risks: safety concerns, routine and additional minimisation measures, effectiveness evaluation, educational materials and commitments made to authorities.

Risk minimisation is a commitment with an effectiveness obligation attached. Distributing an educational pack is an activity; showing that prescribing behaviour changed is the requirement, and the two are routinely confused.

HOW IT FAILS

  • Effectiveness is measured by distribution volume rather than by whether behaviour or outcomes changed.
  • Additional measures accumulate across markets with no assessment of whether the earlier ones worked.
  • Commitments are tracked by regulatory affairs while implementation sits elsewhere, and the two diverge.

WHAT CONTAINS IT

  • Effectiveness indicators defined when the measure is proposed, with a method capable of detecting change.
  • Periodic review of whether existing measures are working before adding more.
  • A single commitment register spanning regulatory obligation and operational implementation.

EVIDENCE IT OPERATES

  • Risk management plans with safety concerns and measures.
  • Effectiveness evaluation results and resulting changes.
  • Commitment register with implementation evidence.
06

Complaints, device vigilance & product surveillance

Product complaints and device vigilance: intake, reportability assessment, investigation, regulatory vigilance reporting, trending and the interfaces to quality and manufacturing.

A complaint is simultaneously a quality signal and potentially a reportable safety event, and the two assessments run on different clocks. Where intake is single-threaded through quality, the vigilance timeline can expire during the technical investigation.

HOW IT FAILS

  • Reportability is assessed after the technical investigation concludes, by which time the reporting clock has run.
  • Complaints are trended by product and not by failure mode, so a recurring mechanism across products is invisible.
  • Complaints closed as "no fault found" are not trended, discarding the pattern they collectively form.

WHAT CONTAINS IT

  • Reportability assessed on intake, in parallel with and not after the technical investigation.
  • Trending by failure mode and mechanism as well as by product.
  • No-fault-found complaints trended explicitly, with a threshold that triggers deeper investigation.

EVIDENCE IT OPERATES

  • Complaint records with intake, reportability decision and investigation.
  • Vigilance and MDR submissions with timeliness metrics.
  • Trending across failure modes including no-fault-found outcomes.
07

Postauthorization studies & real-world evidence

Evidence generated after authorisation: post-authorisation safety studies, post-market clinical follow-up, registries, observational evidence, protocols, data fitness and reporting.

Postmarket studies answer questions the trials could not, and they are frequently conditions of approval. Their weakness is data fitness — real-world data were collected for another purpose, and whether they can support the question is a judgement that must be made explicitly.

HOW IT FAILS

  • A real-world data source is adopted for its size without assessing whether it captures the outcome of interest.
  • Study commitments are tracked as regulatory milestones with no oversight of feasibility until recruitment fails.
  • Results are reported to the authority and never routed into benefit-risk or labelling review.

WHAT CONTAINS IT

  • Data fitness assessed against the specific question before a source is selected.
  • Feasibility monitored during conduct with early escalation when a commitment is at risk.
  • Results routed into safety governance and labelling review as a defined step.

EVIDENCE IT OPERATES

  • Study protocols with data-source fitness assessment.
  • Commitment tracking with feasibility and progress reporting.
  • Study reports and the benefit-risk or labelling decisions taken from them.
08

Recalls, field actions & safety communications

Acting on product already distributed: health-hazard evaluation, scope determination, coordination with authorities, execution, effectiveness checks and closure.

A field action is the point where every other system is tested at once — traceability determines the scope, distribution records determine reach, and the effectiveness check determines whether the product actually came back. Weakness anywhere widens the action.

HOW IT FAILS

  • Scope is set by batch genealogy that proves incomplete, so the action is expanded mid-execution.
  • Effectiveness is measured by notification sent rather than by product recovered or corrected.
  • Root cause is closed before the action completes, so recurrence risk is judged on partial information.

WHAT CONTAINS IT

  • Health-hazard evaluation and scope determination by a defined multidisciplinary decision, documented.
  • Effectiveness measured by response and recovery rate with escalation for non-responders.
  • Root-cause completion tracked separately from action closure, both to defined criteria.

EVIDENCE IT OPERATES

  • Health-hazard evaluations and scope decisions with rationale.
  • Distribution and traceability records supporting scope.
  • Effectiveness check results and closure records including root cause.
09

Medical information & product inquiry intelligence

Handling enquiries about the product: scientific responses, enquiry management, escalation of anything that is actually a safety report, trend signals, content control and interfaces to safety and quality.

Medical information is a high-volume front door through which adverse events and complaints arrive disguised as questions. It is also where the enquiry pattern itself is a signal — a spike in questions about administration often precedes reported use errors.

HOW IT FAILS

  • Enquiry handlers screen for explicit adverse-event language and miss reports embedded in a clinical question.
  • Standard response content ages out of alignment with the current approved labelling.
  • Enquiry trends are reported as volume metrics with no clinical review for emerging themes.

WHAT CONTAINS IT

  • Screening criteria and training aimed at recognising an event described indirectly.
  • Response content version-controlled against current labelling with a defined review cycle.
  • Clinical review of enquiry themes, routed to signal management where a pattern emerges.

EVIDENCE IT OPERATES

  • Enquiry records with adverse-event and complaint screening outcomes.
  • Response content library with version control and labelling alignment.
  • Enquiry trend analyses and referrals into signal management.
10

Safety systems, vendors & partner exchange

The infrastructure behind safety: databases, dictionaries, interfaces, partner agreements, reconciliation, timeline management, vendor oversight and the evidence an inspector will ask for.

Safety data arrive from partners, vendors and affiliates, and every exchange is a place where a case can be delayed or lost. Reconciliation is the control that finds those losses, and it only works if it is periodic and two-way.

HOW IT FAILS

  • Reconciliation with partners is annual, so a case lost in transfer is discovered long after its reporting clock expired.
  • Dictionary versions differ between partners, so the same event codes differently on each side.
  • Safety data exchange agreements exist with commercial partners but not with distributors and licensees who also receive reports.

WHAT CONTAINS IT

  • Periodic two-way reconciliation at a frequency short enough to protect reporting timelines.
  • Dictionary version alignment agreed and verified across every exchanging party.
  • Safety data exchange agreements covering every party that may receive a report, including distributors.

EVIDENCE IT OPERATES

  • Reconciliation records with discrepancies and resolution.
  • Dictionary version control and upgrade records.
  • Safety data exchange agreements and partner oversight records.

Why it matters in regulated work

  • Maintains the benefit-risk view after clinical development and market entry.
  • Connects cases, complaints, literature, studies, signals, field actions, and authority reporting.
  • Requires partner responsibilities and data exchange to remain complete and timely.

Principal failure modes

  • Safety information is late, incomplete, or fragmented
  • Signals are not escalated or evaluated consistently
  • Risk minimization or field action does not reach affected users

Control objectives

  • Capture and assess safety information
  • Detect, validate, prioritize, and govern signals
  • Communicate risk and verify effectiveness of action

Evidence families

  • Cases, complaints, literature, and reconciliation records
  • Signal assessments, aggregate reports, and benefit-risk decisions
  • Risk-management measures, communications, field actions, and effectiveness checks

CONNECTED OPERATING MODEL

Where this capability connects

Lifecycle reach

  • Clinical Development
  • Regulatory Submission & Approval
  • Commercial Manufacturing
  • Packaging & Serialisation
  • Storage & Distribution
  • Pharmacovigilance
  • Post-Market Surveillance
  • Discontinuation & Record Retention

Quality capabilities

  • Deviation & Investigation Management
  • CAPA
  • Quality Risk Management
  • Supplier Quality
  • Data Governance
  • Regulatory Intelligence
  • Process Monitoring

System classes

  • Safety / PV Database
  • eQMS
  • RIM

Roles to start with

  • Pharmacovigilance Associate
  • Complaint & Vigilance Specialist
  • Regulatory Affairs Associate

MATURITY ORIENTATION · SPEQ SYNTHESIS

What stronger operation looks like

  1. 01ReactiveOwnership and evidence are reconstructed after events; controls depend on individuals.
  2. 02DefinedScope, roles, methods, records, and escalation are documented for routine use.
  3. 03ControlledCritical controls are risk-based, verified, monitored, and governed through change.
  4. 04PredictiveLeading signals connect performance, drift, capacity, risk, and intervention.
  5. 05AdaptiveLearning improves the operating model without weakening accountability or evidence.

HIGH-VALUE INTERSECTIONS

SOURCE BASIS

REGULATORY BASIS

What governs this capability

The 12 standards SPEQ maps to this pillar, and the 5 regulatory bodies behind them. Which standards belong to a pillar is a SPEQ judgement; the bodies, disciplines and industries below are read from the standards themselves.

DISCIPLINES

BODIES

EC · EMA · FDA · ICH · VICH

Also reached through the systems this pillar runs on

These 13 standards govern the system classes this pillar depends on rather than the pillar itself. The distinction matters: a standard that governs a system is not thereby a standard of every capability that uses it.

21 CFR Part 31221 CFR Part 11ISPE GAMP 5 (2022)ICH Q10ICH Q9(R1)21 CFR Part 21121 CFR Part 820ISO 13485:2016ISO 9001:2015EU GMP Annex 11MHRA GxP DI (2018)ICH Q12EU GMP Annex 16

PROFESSIONAL · READINESS ORIENTATION

Turn the pillar into a bounded operating conversation.

Rate observable operation from 0 (not established) to 4 (adaptive). The protected output prioritizes operating dimensions and evidence—not a compliance score.