PV Audits & Inspections
A pharmacovigilance system is only as reliable as its oversight. GVP requires marketing-authorisation holders to audit their pharmacovigilance system on a risk-based schedule, feed the findings into corrective and preventive action, and stand ready for inspection by competent authorities. Audits and inspections are where the paper description of the PV system — the pharmacovigilance system master file, the procedures, the QPPV’s oversight — is tested against what the system actually does. Failures here are systemic, because a broken PV oversight loop means safety signals may be missed anywhere.
What an explainer is not
A topic explainer is SPEQ’s synthesis of what a practice involves, cited to the standards that govern it. It does not reproduce their text, and it does not determine which of them apply to your product or process.
[ POSITION IN THE FRAMEWORK ]
7 DIMENSIONS · 20 LINKSA pharmacovigilance system is only as good as its oversight: GVP and the quality-system discipline require risk-based PV audit, a CAPA loop that actually closes, and a PSMF that matches reality when a competent authority inspects.
06 · QUALITY MATURITY — PV AUDITS & INSPECTIONS, REACTIVE TO ADAPTIVE
PV audit is absent or ad hoc; the PSMF describes an aspirational system, and findings — where raised — are not closed.
A PV audit programme exists on a flat rotation, and CAPAs fix instances without addressing root cause, so findings recur.
Audits are risk-based and reach delegated activities; findings drive root-cause CAPA tracked to verified closure.
Audit intelligence concentrates on the real risk interfaces — affiliates, vendors, case intake — and repeat findings fall as causes are fixed.
Inspection readiness is a continuous state: the PSMF matches reality, the QPPV has genuine oversight, and the audit loop demonstrably works.
SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →
07 · REGULATORY & EVIDENCE
GOVERNING STANDARDS · 3
Derived from the 3 standards SPEQ maps to this subject, across 3 regulatory bodies: ICH, EMA, FDA.
RECORDS & OBJECTIVE EVIDENCE
- A documented, risk-based PV audit strategy ranking areas and interfaces
- Audit reports covering delegated activities (affiliates, partners, vendors)
- CAPA records with root cause, action, and verified effectiveness
- A pharmacovigilance system master file matching the real system
- Evidence of QPPV oversight of system performance
COMMON INSPECTION FINDINGS
- PV audits absent, or on a flat rotation ignoring risk
- Delegated or outsourced PV activities excluded from the audit scope
- CAPAs correcting the instance without addressing root cause
- Critical or major findings left open or closed without effectiveness evidence
- PSMF describing a system that does not match reality
The quality system behind pharmacovigilance
GVP treats pharmacovigilance as a quality-managed activity in its own right, with a defined quality system: documented processes, trained and adequately resourced staff, record and data management, and mechanisms for monitoring performance — the PV quality-system requirements. Audit is the independent assurance layer over that quality system — the mechanism that checks the PV system is doing what it claims, not just that it exists on paper.
The Qualified Person Responsible for Pharmacovigilance (QPPV) sits at the centre of this oversight, with responsibility for the overview of the system’s functioning. Audit does not replace the QPPV’s oversight; it independently verifies it. SPEQ synthesis: the healthiest PV organisations treat audit findings not as a scorecard but as intelligence about where the system’s real risks concentrate — the interfaces with affiliates and vendors, the case intake channels, the signal-detection cadence.
Risk-based PV auditing
PV audits are planned on risk, not on a flat rotation. An audit strategy identifies the areas of the pharmacovigilance system, its processes, and its interfaces, ranks them by risk to patient safety and compliance, and schedules audits so the highest-risk areas are examined most rigorously and most often. The strategy is documented and revisited as the risk picture changes.
The scope reaches beyond the MAH’s own walls. Pharmacovigilance is frequently delegated — to affiliates, licensing partners, contract organisations, and vendors handling case processing or literature screening — and delegated activities are exactly where obligations fall between the cracks. A risk-based audit programme reaches into those interfaces, because a signal missed by an outsourced case-intake vendor is the MAH’s failure, not the vendor’s.
The CAPA loop
Findings from PV audits feed a corrective and preventive action process. A finding names what is wrong; the CAPA establishes the root cause, the correction, the preventive action to stop recurrence, and the verification that the action worked. Critical and major findings are tracked to closure with particular rigour, because an open critical finding in pharmacovigilance is an open risk to patient safety.
The most common weakness inspectors find is not the absence of CAPAs but their shallowness — corrections that fix the instance without addressing the cause, or actions marked closed without evidence of effectiveness. A CAPA that retrains an individual for a failure that was really a process design flaw will not prevent recurrence, and inspectors read a pattern of repeat findings as proof the CAPA loop is not actually closing.
What a GVP inspection examines
Competent-authority pharmacovigilance inspections test the system end to end: whether the pharmacovigilance system master file accurately describes the real system; whether the QPPV has the standing, resources, and oversight to do the role; whether individual case safety reports are collected, assessed, and reported within timelines; whether signal management, periodic reports, and the RMP function; and whether the audit-and-CAPA loop is real. Inspections may be routine (scheduled) or triggered by a specific concern.
Inspection readiness is a state, not a project. Because the system is expected to work continuously, an MAH cannot credibly "prepare" for an inspection by fixing things beforehand — the master file must already match reality, the QPPV must already have oversight, and the audit history must already show findings being closed. SPEQ synthesis: the single best inspection-readiness investment is an honest internal audit programme whose findings the organisation actually acts on, because it surfaces the same gaps an inspector would, on the organisation’s own terms.
FREQUENTLY ASKED
How often must a pharmacovigilance system be audited?
GVP requires audits to be planned on a risk-based schedule rather than a fixed rotation. A documented audit strategy ranks the areas, processes, and interfaces of the PV system by risk to patient safety and compliance, and schedules audits so the highest-risk areas are examined most rigorously and most often, with the strategy revisited as the risk picture changes.
Do pharmacovigilance audits cover outsourced activities?
Yes. Pharmacovigilance is often delegated to affiliates, licensing partners, and vendors handling case processing or literature screening, and those interfaces are where obligations most easily fall through the cracks. A risk-based PV audit programme must reach into delegated activities, because a failure by an outsourced provider remains the marketing-authorisation holder’s responsibility.
What does a GVP inspection look at?
End-to-end: whether the pharmacovigilance system master file matches reality, whether the QPPV has genuine oversight and resources, whether individual case safety reports are collected and reported on time, whether signal management, periodic reporting, and the RMP function, and whether audit findings are driven to closure through effective CAPA. Inspections may be routine or triggered by a specific concern.