Outsourced Pharmacovigilance: Auditing the Partners Who Run Your Safety System

Very few marketing authorisation holders run every part of their pharmacovigilance system in-house. Case processing, literature screening, local safety contacts and database hosting are routinely delegated to service providers and affiliates. The obligation, however, is never delegated. Under Regulation (EU) 2025/1466, which has applied since February 2026, the expectation that an MAH can demonstrate oversight of everything done in its name has become sharper — and audit programmes are where inspectors look for the evidence.

Delegation without transfer of accountability

This is the principle that catches companies out. A contract can move an activity to a vendor; it cannot move the legal responsibility. If a service provider misses an expedited reporting deadline, the finding lands on the MAH. If an affiliate collects adverse event reports through a local email address that never reaches the global safety database, the gap belongs to the MAH.

The practical consequence is that the pharmacovigilance system master file must describe the system as it actually operates, including the full chain of subcontracting. Where a vendor has in turn subcontracted part of the work — translation, medical review, archiving — that second tier needs to be visible too. A PSMF that describes an idealised system rather than the real one is a finding waiting to happen.

Building an audit programme that stands up

Audits of pharmacovigilance activities should be planned on a risk-based interval rather than a fixed rota, covering the activities performed by the MAH and by its subcontractors across a defined period. In practice that means:

  • A current inventory of who does what. You cannot audit a system you have not mapped. Contracts, safety data exchange agreements and the PSMF should agree with each other.
  • Risk-ranking the partners. A vendor processing thousands of cases for a high-volume product carries different risk from one hosting an archive. Frequency and depth should reflect that.
  • Auditing the interfaces, not just the parties. Most failures occur in handovers — between affiliate and vendor, between vendor and database, between medical information and safety.
  • Following through on CAPA. An audit finding with no evidence of effective corrective action is worse than no audit, because it documents a known problem left unresolved.

Where safety data exchange agreements fail

SDEAs are often signed at the start of a relationship and never revisited. Common weaknesses include timelines that do not reconcile with regulatory clocks once the partner’s own internal steps are counted, silence on who reconciles case counts and how often, no defined route for urgent safety issues outside business hours, and no provision for what happens to safety data when the contract ends.

Reviewing these agreements is unglamorous work, but it is considerably cheaper than discovering the gaps during an inspection.

How PQRA helps

PQRA supports marketing authorisation holders across the full pharmacovigilance system, including QPPV provision, PSMF authoring and maintenance, and inspection readiness. We map outsourced activities against contractual and regulatory obligations, design and run risk-based audit programmes covering vendors and affiliates, review and renegotiate safety data exchange agreements, and help close findings with corrective actions that hold up on re-inspection.

If your safety system depends on partners, your oversight of those partners is your compliance position. Get in touch with PQRA to review how yours would look to an inspector.

CATEGORIES:

Uncategorized

Tags:

No responses yet

Leave a Reply

Your email address will not be published. Required fields are marked *