ICSRs & Expedited Reporting
Everything in pharmacovigilance is built from one unit: the Individual Case Safety Report (ICSR), the structured record of an adverse event experienced by one patient taking one or more suspect medicines. Expedited reporting is the obligation to send certain of those cases to regulators fast — on a defined clock — because they signal something potentially new and serious. Getting this layer right is foundational: a mishandled case-validity judgement, a confusion of "serious" with "severe", or a missed expedited clock is both a safety failure and a compliance finding. This page is the mechanics of the case and its timeline; the periodic and signal-level views that sit on top of it are the [signal management](/topics/signal-management) and [periodic safety reporting](/topics/periodic-safety-reporting) explainers. ICH E2A, ICH E2B(R3), EU good pharmacovigilance practice, and 21 CFR 314.80 define the framework.
What an explainer is not
A topic explainer is SPEQ’s synthesis of what a practice involves, cited to the standards that govern it. It does not reproduce their text, and it does not determine which of them apply to your product or process.
[ POSITION IN THE FRAMEWORK ]
7 DIMENSIONS · 20 LINKSThe ICSR is the atom of pharmacovigilance: four criteria make a case valid, seriousness (not severity) sets the obligation, and serious-plus-unexpected starts the 15-day expedited clock that all downstream safety work is built on.
06 · QUALITY MATURITY — ICSRS & EXPEDITED REPORTING, REACTIVE TO ADAPTIVE
Cases are logged inconsistently; severity is mistaken for seriousness and 15-day clocks are missed because validity is judged case by case.
An SOP defines the four validity criteria and seriousness, but expectedness rests on an out-of-date reference and follow-up reporting is patchy.
Validity, seriousness, and expectedness are assessed against a maintained reference; the expedited clock is tracked and E2B(R3) cases flow as data.
Reporting-compliance and case-quality metrics are trended; poorly coded cases and reconciliation gaps are caught before they distort signal detection.
Case intake, coding, and submission run as a governed pipeline; case quality is managed as safety quality and feeds automated signal detection cleanly.
SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →
07 · REGULATORY & EVIDENCE
GOVERNING STANDARDS · 4
Derived from the 4 standards SPEQ maps to this subject, across 3 regulatory bodies: EMA, FDA, ICH.
RECORDS & OBJECTIVE EVIDENCE
- ICSRs recording the four validity criteria and coded (MedDRA) event terms
- Seriousness and expectedness assessments against a maintained reference safety document
- Expedited (commonly 15-day) submission records with the reporting clock evidenced
- Follow-up versions of cases with reconciliation between reporting partners
- E2B(R3) structured transmissions into EudraVigilance / FAERS
COMMON INSPECTION FINDINGS
- Severity recorded as seriousness, or a serious case downgraded, miscategorising the report
- The 15-day expedited clock missed on a serious, unexpected case
- Expectedness judged against an inaccurate or outdated reference document
- Valid four-criteria cases discarded instead of followed up
- Poorly coded cases left invisible to downstream signal detection
What makes a valid case: the four minimum criteria
A report is only a valid ICSR when four elements are present: **an identifiable patient**, **an identifiable reporter**, **at least one suspect medicine**, and **at least one adverse event**. Miss any one and the report is not yet a valid case — but "not valid" does not mean "discard": the pharmacovigilance system must attempt to follow up and obtain the missing element, because an incomplete report of a serious event still matters. The four criteria are the gate that decides when the reporting clock starts and what enters the safety database, so they are applied consistently rather than by individual judgement.
Around those minimums sits the information that makes a case useful: patient demographics, the event described in clinical terms and coded (typically in MedDRA), the suspect and concomitant medicines with doses and dates, the outcome, and the reporter’s causality view. A case is also a living record — follow-up can upgrade its seriousness, add the missing reporter, or change the assessment, and each meaningful update is itself a version of the case that may restart or reset obligations. Treating an ICSR as a one-time form rather than a record that evolves is a common source of missed follow-up reporting.
Seriousness is not severity — the distinction that drives everything
The most consequential confusion in case processing is between seriousness and severity, because one is a clinical descriptor and the other is a regulatory trigger. **Severity** describes the *intensity* of an event — mild, moderate, or severe — and is a matter of clinical degree. **Seriousness** is a defined regulatory category: an event is serious if it results in death, is life-threatening, requires or prolongs hospitalisation, causes persistent or significant disability or incapacity, is a congenital anomaly or birth defect, or is another medically important condition. Seriousness, not severity, determines the reporting obligation.
The examples make the gap concrete: a **severe headache** (high intensity) may be entirely non-serious, while a **mild myocardial infarction** (low intensity) is serious by definition because of what it is. A case-processing operation that files a "severe" event as serious, or downgrades a "mild" serious event, has miscategorised the very thing the expedited clock hangs on. This is why seriousness is assessed against the regulatory criteria for every case, independent of how intense the reporter said the event felt.
What triggers an expedited report: serious + unexpected
Not every serious case is reported on the fast clock. The expedited trigger is the combination of **serious** and **unexpected** — an event that is not already listed, in nature or severity, in the product’s reference safety information. Expectedness is judged against a defined reference (the company core data sheet or the approved label’s safety information), which is why maintaining an accurate reference safety document is itself a pharmacovigilance control: widen or narrow it wrongly and every expectedness decision downstream is wrong. A serious *and* unexpected case (an unexpected adverse reaction) generally must be reported to regulators on an expedited basis — commonly within **15 calendar days**, with tighter handling for fatal or life-threatening cases in some frameworks.
The US and EU frameworks express the same logic in their own instruments. **ICH E2A** provides the definitions and the clinical-safety-data-management framework the whole system rests on; in the US, **21 CFR 314.80** requires 15-day "alert reports" for serious, unexpected postmarketing adverse experiences; and the EU good-pharmacovigilance-practice modules govern expedited submission to EudraVigilance. A serious-but-expected case is not usually individually expedited but is captured cumulatively and re-evaluated in periodic reporting — which is why the case layer and the periodic layer are two halves of one obligation.
E2B(R3): cases are data, not documents
Modern pharmacovigilance does not exchange ICSRs as prose. **ICH E2B(R3)** is the international standard for the electronic structure and transmission of an individual case — the defined data elements and message format that let cases move between companies, partners, and regulator databases without manual re-keying. It is the reason a case captured by a marketing-authorisation holder can flow into EudraVigilance or FAERS as structured data that supports automated signal detection, and it is the practical backbone that makes large-scale pharmacovigilance possible at all.
The consequence for practice is that data quality *is* safety quality here. Because downstream signal detection runs on the coded, structured fields — MedDRA terms, seriousness flags, drug roles, dates — a case that is clinically well understood but poorly coded is partially invisible to the systems meant to find the pattern. Reconciliation between partners (the same case reported by two parties must not become two signals) and correct versioning of follow-ups are therefore not clerical details but part of keeping the safety database an accurate reflection of the real world. The ICSR is the atom; E2B(R3) is what lets the atoms add up.
FREQUENTLY ASKED
What are the four minimum criteria for a valid ICSR?
An identifiable patient, an identifiable reporter, at least one suspect medicine, and at least one adverse event. Without all four the report is not yet a valid case — but it is not discarded: the pharmacovigilance system must follow up to obtain the missing element, because an incomplete report of a serious event still matters. The four criteria decide when the reporting clock starts and what enters the safety database.
What is the difference between seriousness and severity?
Severity describes the intensity of an event (mild, moderate, severe) — a clinical degree. Seriousness is a defined regulatory category: death, life-threatening, hospitalisation or its prolongation, persistent/significant disability, congenital anomaly, or another medically important condition. Seriousness drives the reporting obligation, not severity. A severe headache may be non-serious; a mild myocardial infarction is serious by definition.
What triggers an expedited (15-day) report?
The combination of serious and unexpected — a serious event not already listed, in nature or severity, in the product’s reference safety information. Such cases generally must be reported to regulators on an expedited basis, commonly within 15 calendar days (with tighter handling for fatal or life-threatening cases in some frameworks). Expectedness is judged against the company core data sheet or approved label, so maintaining that reference accurately is itself a pharmacovigilance control.
What is ICH E2B(R3)?
The international standard for the electronic structure and transmission of an individual case safety report — the defined data elements and message format that let cases move between companies and regulator databases (EudraVigilance, FAERS) as structured data rather than prose. Because downstream signal detection runs on those coded fields, a clinically sound but poorly coded case is partially invisible to the systems meant to find the pattern.