Drug safety and pharmacovigilance complete guide featured image showing a pharmacovigilance professional at a laptop with a PV dashboard, PV System binder, pharmacovigilance medicine, and a safety report checklist covering data quality, causality assessment, benefit-risk evaluation, and regulatory compliance, with a pharmacovigilance wheel diagram covering ICSR processing, signal detection, PBRER reporting, and risk management plans.

Drug Safety and Pharmacovigilance: A Complete Guide for Healthcare and Industry Professionals

GUIDE: Drug Safety and Pharmacovigilance
Drug Safety and Pharmacovigilance: A Complete Guide for Healthcare and Industry Professionals
Pharmacovigilance is the science and activity of detecting, assessing, understanding, and preventing adverse effects and other drug-related problems. Every marketed medicine has a pharmacovigilance obligation attached to it, and every healthcare professional, patient, and pharmaceutical employee who encounters a safety signal has a role in the system. This guide explains what pharmacovigilance requires, who is responsible for what, and how to build and operate an effective drug safety programme from clinical trials through post-market surveillance.
Quick Overview
What Pharmacovigilance Is
The WHO defines pharmacovigilance as the science and activities relating to the detection, assessment, understanding, and prevention of adverse effects or any other drug-related problem. It encompasses all safety activities from pre-clinical development through post-marketing surveillance, and applies to medicines, biologics, vaccines, herbal products, blood products, and medical devices in many regulatory frameworks.
Who It Applies To
Marketing Authorisation Holders (MAHs) have primary legal responsibility for pharmacovigilance of their products. Healthcare professionals have reporting obligations under national regulations. Patients have reporting rights through national pharmacovigilance databases. Contract research organisations and contract safety organisations perform delegated PV activities on behalf of MAHs. Regulatory agencies receive, assess, and act on the safety data generated by all of these stakeholders.
Regulatory Basis
In the US: FDA regulations under 21 CFR Parts 310, 312, and 314; FDA Guidance on Safety Reporting Requirements. In the EU: Regulation (EC) No 726/2004 and Directive 2001/83/EC as amended by Directive 2010/84/EU; EMA’s Good Pharmacovigilance Practices (GVP) modules. Globally: ICH E2 series guidelines (E2A through E2F) harmonise safety reporting across ICH member regions.
Typical Programme Components
Individual Case Safety Report (ICSR) collection and submission, signal detection and evaluation, periodic safety reports (PSURs/PBRERs), Risk Management Plans (RMPs), benefit-risk assessment, pharmacovigilance system master file (PSMF), literature monitoring, Qualified Person for Pharmacovigilance (QPPV) oversight, and regulatory agency interactions on safety topics.
What You Will Learn
The ICH E2 series and how each guideline defines your safety reporting obligations
How to structure Individual Case Safety Report collection and submission workflows
How signal detection works and what triggers a signal evaluation
What a Pharmacovigilance System Master File must contain and how to maintain it
How to design and implement a Risk Management Plan
The most common pharmacovigilance audit findings and how to prevent them
How benefit-risk assessment is conducted across the product lifecycle
How to prepare for regulatory pharmacovigilance inspections

Prerequisites

Understand the product’s regulatory status and approval history
PV obligations differ depending on whether the product is in clinical development, under regulatory review, or marketed. The jurisdiction and regulatory pathway (NDA, BLA, MAA) also determine which specific reporting requirements apply. Confirm the product’s regulatory status and the applicable national regulations in each market where it is authorised before designing the PV programme.
Identify the Qualified Person for Pharmacovigilance
In the EU, every MAH must have a QPPV with defined qualifications and responsibilities. In the US, a designated person responsible for safety reporting must be identified in the NDA/BLA. The QPPV or designated responsible person is the anchor of the PV system; their authority, access, and responsibilities must be defined before the system is operational.
Map all sources of safety information
Safety information reaches MAHs through multiple channels: clinical trial sites, healthcare professionals, patients, literature, social media, regulatory agencies, business partners, and post-market studies. Before building case processing workflows, map every channel through which the company may receive adverse event information and ensure each is covered by a triage and intake procedure.

Required Documents and Systems

Document / System
Purpose
Regulatory Basis
Pharmacovigilance System Master File (PSMF)
Central reference document describing the entire PV system structure, staffing, processes, and quality system
EU GVP Module II; required for EU marketing authorisations
Safety database (e.g., Argus, ARISg, Veeva Vault Safety)
Case processing, MedDRA coding, narrative generation, expedited submission, signal detection
Required for case management at scale; FDA and EMA expect validated safety databases
Adverse Event Reporting SOPs
Defines the end-to-end process for ICSR collection, triage, processing, medical review, and submission
21 CFR 314.81; EU GVP Module VI
Risk Management Plan (RMP)
Describes known and potential risks, missing information, and risk minimisation measures
Required for all EU centrally authorised products; encouraged in US
Literature monitoring programme
Systematic weekly or monthly search of scientific literature for adverse event reports and safety signals
EU GVP Module VI; FDA 21 CFR 314.81(b)(2)(i)

Step-by-Step: Building and Operating a Pharmacovigilance Programme

1
Establish the PV System Structure and Governance
Objective: Define who is responsible for what before the first adverse event arrives
Why It Matters
Pharmacovigilance failures almost always start with unclear ownership. When no one is clearly responsible for a safety signal or a reporting deadline, reports are late, signals are missed, and regulatory agencies receive incomplete safety information. The PV governance structure defines the QPPV’s role, the safety team’s responsibilities, the escalation paths for serious signals, and the authority to make safety-driven decisions about product labelling and marketing.
Actions
Appoint a QPPV with appropriate qualifications and a backup QPPV. Define the PV department’s structure and reporting line. Establish a Safety Management Team or equivalent cross-functional body for signal management and benefit-risk decisions. Draft the Pharmacovigilance System Master File. Define the quality system for PV activities including SOPs, training requirements, audit programme, and deviation management.
Expected Outcome
A documented PV system with clear ownership, a qualified QPPV, an operational PSMF, and a set of approved SOPs covering each PV activity. The governance structure should be auditable: an inspector should be able to ask who is responsible for any PV decision and receive a documented answer.
Tip
The PSMF is not a filing exercise. It is a live document that reflects the current state of the PV system. Update it whenever the system changes: when the QPPV changes, when a new product is added, when a PV SOP is revised. An outdated PSMF is a primary finding in PV inspections.
2
Build the ICSR Collection and Submission Workflow
Objective: Ensure every adverse event report is captured, processed, and submitted within regulatory timelines
Why It Matters
Expedited ICSR submission timelines are regulatory requirements with specific clocks. In the EU and US, serious unexpected adverse drug reactions from clinical trials must be submitted within 7 or 15 calendar days depending on whether they are fatal or life-threatening. Serious unexpected post-marketing adverse drug reactions must be submitted within 15 calendar days. Missing these deadlines generates compliance findings and may trigger regulatory action.
Actions
Define the four ICSR validity criteria (identifiable reporter, identifiable patient, suspect drug, adverse event). Build triage procedures for each intake channel. Implement MedDRA coding for adverse event and medical history terms. Establish the medical review step for causality assessment and seriousness determination. Define submission routes for each regulatory authority. Configure the safety database for automatic deadline calculation and submission tracking.
Expected Outcome
An end-to-end ICSR workflow documented in SOPs and validated in the safety database, with defined timelines for each processing step, escalation triggers for priority cases, and submission tracking that provides real-time visibility of pending deadlines.
Warning
Day 0 for ICSR timelines is the date the company first becomes aware of the case, not the date it reaches the PV department. Training commercial teams, medical affairs, and clinical operations on their obligation to forward adverse event information to PV immediately is essential. A day-0 definition that begins at PV receipt rather than company awareness creates systematic late reporting.
3
Implement Signal Detection and Evaluation
Objective: Identify potential new safety signals before they become regulatory surprises
What Signal Detection Involves
Signal detection identifies information suggesting a new, causal relationship between a drug and an adverse event, or a change in the characteristics of a known relationship, that warrants further investigation. Sources include the company safety database, regulatory agency databases (FAERS, EudraVigilance), published literature, and post-market study data. Statistical disproportionality analysis (PRR, ROR, BCPNN) is used for large database signal detection; qualitative case review is used for smaller datasets.
Actions
Define the signal detection frequency for each data source (monthly for the safety database; weekly for literature). Establish the signal evaluation process: what constitutes a valid signal, who evaluates it, what the timeline is, and what the output must be. Document signal evaluations and their outcomes. Connect the signal evaluation process to labelling update and RMP revision procedures so that validated signals result in appropriate action.
Expected Outcome
A documented signal detection and management process with defined frequencies, evaluation criteria, escalation paths, and a signal tracking log. Regulatory agencies assess signal management during PV inspections; a signal tracking log that shows identified signals, their evaluation, and their resolution is the primary evidence of a functional signal management programme.
Tip
Signal detection is not only a mathematical exercise. A case series of three or four reports of a serious, unexpected adverse event may warrant signal evaluation before statistical thresholds are reached. Disproportionality analysis supplements clinical judgment; it does not replace it.
4
Develop and Maintain the Risk Management Plan
Objective: Document the known, potential, and missing safety information for each product and define how risks are minimised
Why It Matters
The RMP is required for all EU centrally authorised products and increasingly expected by FDA for products with significant safety concerns. It provides the regulatory framework within which post-marketing commitments, additional risk minimisation measures (educational materials, REMS programmes), and post-authorisation safety studies are managed. An outdated RMP that does not reflect current safety knowledge is a regulatory compliance failure and a patient safety risk.
Actions
Structure the RMP using the EMA template: safety specification (known risks, potential risks, missing information), pharmacovigilance plan, risk minimisation measures, and summary of activities. Update the RMP whenever new safety information changes the benefit-risk profile. Submit RMP updates to regulatory agencies as required by the marketing authorisation conditions. Track RMP version history and regulatory submissions carefully.
Expected Outcome
A current, approved RMP for each product reflecting the most recent safety knowledge, with a documented process for RMP review and update triggered by safety signal validation, periodic benefit-risk review, and regulatory request.
Tip
Align RMP updates with PSUR/PBRER submissions wherever possible. Both documents draw from the same safety database and safety specification; preparing them together reduces duplication of effort and ensures consistency between the two documents presented to the same regulators.
5
Prepare and Submit Periodic Safety Reports
Objective: Provide regulators with cumulative benefit-risk assessments at defined intervals
PSUR vs PBRER
The Periodic Safety Update Report (PSUR) is the EU term; the Periodic Benefit-Risk Evaluation Report (PBRER) is the ICH E2C(R2) harmonised format adopted by FDA and EMA. Both present cumulative safety data, updated benefit-risk assessment, and any changes in the safety specification since the previous reporting period. The International Birth Date (IBD) sets the data lock point for periodic reports in ICH countries.
Actions
Identify the IBD and reporting frequency for each product in each jurisdiction. Build a PBRER/PSUR schedule and assign writing, medical review, and QC responsibilities. Ensure cumulative ICSR data is extracted from the safety database in a format suitable for PBRER tabulations. Submit the PBRER on time through the required submission pathways (EU: EMA EVWEB; US: FDA ESG; others: country-specific portals).
Expected Outcome
On-time PBRER submissions for each product in each jurisdiction, with a documented schedule that is reviewed and updated as regulatory requirements change. Late PBRER submissions are frequently cited in PV inspection findings and can trigger additional regulatory scrutiny.
Warning
PBRER frequency can change following significant safety actions. After a label update for a new serious adverse reaction, regulators may require more frequent PBRER submissions. Build a process to monitor regulatory feedback on PBRERs and update the submission schedule accordingly.
6
Build and Operate the PV Quality System
Objective: Ensure the PV system operates consistently and is ready for regulatory inspection at any time

A pharmacovigilance quality system encompasses the SOPs, training programme, audit programme, deviation management system, and CAPA process that govern PV activities. Regulatory PV inspections assess the quality system as a primary indicator of the PV system’s reliability. A well-written PSMF backed by an audit-ready quality system is the foundation of inspection readiness.

SOPs
Cover every PV activity: ICSR intake, triage, processing, literature monitoring, signal detection, PBRER preparation, RMP maintenance, PSMF maintenance, training, deviations, and audit. SOPs must be current, approved, and actually followed.
Training
Role-specific PV training for all personnel with PV responsibilities, including commercial teams who are the first point of contact for many adverse event reports. Training records must be current and available for inspection.
Audit Programme
Periodic internal audits of PV activities and annual audits of contracted PV partners. Audit findings entered into the CAPA system with effectiveness verification. Audit history and CAPA closure records are the primary inspection-readiness evidence for the quality system.

Best Practices

Train commercial teams on adverse event reporting obligations
Sales representatives and medical affairs personnel are often the first company contact point for adverse event reports from healthcare professionals. Training them to recognise reportable information and forward it to PV on the same day is the single most effective way to prevent systematic late reporting. Day 0 awareness training is not optional.
Validate your safety database before it is operational
A safety database used for ICSR processing and regulatory submissions must be validated for its intended purpose. Validation must cover the case entry, MedDRA coding, narrative generation, submission gateway integration, and deadline calculation functions. Using an unvalidated safety database for regulatory submissions creates both a compliance risk and a data integrity risk.
Conduct mock PV inspections before regulatory inspections
PV inspections assess the PSMF, SOPs, training records, ICSR processing records, signal management logs, and PBRER submissions. Conducting a mock inspection against the EMA or FDA inspection guidance annually identifies gaps while there is time to close them. An organisation that finds its first PSMF currency gap during a regulatory inspection has found it too late.

Common Mistakes

Mistake
What to Do Instead
Defining Day 0 as the date PV receives the case rather than the date the company first becomes aware
Train all customer-facing functions on immediate forwarding of adverse event information to PV. Day 0 is the earliest date any company employee becomes aware of the case, regardless of which function received the information.
Maintaining an outdated PSMF that does not reflect current system structure or QPPV
Review and update the PSMF at least annually and whenever a significant system change occurs. The PSMF must reflect the current system, not the system as it was when the PSMF was written.
Using a single global SOP that does not address country-specific requirements
Build a global/local SOP structure where the global SOP sets the baseline and local addenda address country-specific timelines, submission portals, and local language requirements. Regulators assess local compliance against local requirements, not global standards.
Treating literature monitoring as a one-time database search rather than an ongoing programme
Literature monitoring must be systematic, documented, and ongoing. Define the search terms, databases, and frequency; document each search and its results; triage any identified cases against ICSR validity criteria; and process valid cases through the normal ICSR workflow.

Compliance Notes

Key Regulatory References
ICH E2A: Definitions and standards for expedited reporting. Defines serious adverse event, unexpected adverse reaction, and the reporting timelines for clinical trials.
ICH E2C(R2) / PBRER: The harmonised format for periodic benefit-risk evaluation reports. Adopted by FDA and EMA; replaces the previous PSUR format for ICH-harmonised submissions.
ICH E2D: Post-approval safety data management. Defines case collection requirements, narrative writing standards, and the ICH ICSR format for post-marketing cases.
ICH E2E: Pharmacovigilance Planning. Provides guidance on developing pharmacovigilance plans during clinical development and the structure of the safety specification that feeds into the RMP and PBRER.
EMA GVP Modules I-XVI: EMA’s Good Pharmacovigilance Practices modules cover all aspects of PV system design and operation for EU-authorised products. GVP Module II (PSMF), VI (Management and Reporting of ADRs), IX (Signal Management), and X (Additional Monitoring) are particularly foundational.

Troubleshooting

ICSR submission deadline is about to be missed
Submit whatever minimum valid information is available before the deadline rather than waiting for complete information. Regulatory agencies can accept follow-up reports with additional information. A late initial report with complete information is more serious than an on-time initial report with minimum information followed by a timely follow-up.
Safety database is unavailable during an expedited reporting deadline
Every PV system must have a documented manual backup procedure for expedited report submission when the safety database is unavailable. The manual procedure must include the submission format, the submission pathway, and the data entry requirements for reconciliation when the system is restored. A system outage is not a regulatory excuse for a late submission.
A potential safety signal is identified that may require urgent labelling action
Convene the Safety Management Team immediately for an expedited signal evaluation. If the evaluation confirms a safety concern warranting labelling action, initiate the regulatory variation process without waiting for the scheduled PBRER. Proactive safety communication to regulators before they identify the signal themselves results in substantially better outcomes than reactive responses to agency-initiated signal assessments.

Quick Checklist: Pharmacovigilance Programme

System and Governance
QPPV appointed with documented responsibilities
PSMF current and approved
All PV SOPs approved and version-controlled
Training records current for all PV staff
Case Processing
Safety database validated and operational
All intake channels covered by triage procedure
Expedited reporting submission schedule current
Literature monitoring programme active and documented
Signal and Reporting
Signal detection programme with defined frequency
PBRER/PSUR schedule current for each product
RMP current for each EU-authorised product
PV audit programme with findings in CAPA system

Key Takeaways

Day 0 is when the company knows, not when PV receives the case
The most consequential single knowledge gap in pharmaceutical PV is the misunderstanding of Day 0. Training every customer-facing function on immediate forwarding of adverse event information, and building Day 0 correctly into submission timeline calculations, prevents the systematic late reporting that is the most common PV inspection finding worldwide.
Signal detection requires both statistical tools and clinical judgment
Disproportionality analysis from large databases provides a quantitative signal detection tool but does not replace the clinical assessment of case series, literature signals, and data from post-market studies. A PV programme that relies exclusively on statistical thresholds will miss signals that are clinically significant but not yet statistically apparent. The combination of quantitative and qualitative signal assessment is the standard regulatory agencies expect.
Inspection readiness is an ongoing state, not a pre-inspection project
Organisations that achieve and maintain PV inspection readiness do so by operating their PV quality system continuously, not by conducting remediation exercises in the weeks before an announced inspection. The PSMF must be current today. Training records must be current today. The signal tracking log must reflect today’s signal management activity. A PV system that is current only when an inspection is expected is not a functional PV system; it is a documentation exercise.

Frequently Asked Questions

What is the difference between an adverse event, an adverse drug reaction, and a serious adverse event?
An adverse event (AE) is any untoward medical occurrence in a patient administered a medicinal product, whether or not it has a causal relationship with the treatment. An adverse drug reaction (ADR) is a response to a drug that is noxious and unintended, where a causal relationship between the drug and the event is at least reasonably possible. A serious adverse event or reaction is one that results in death, is life-threatening, requires hospitalisation or prolongation of hospitalisation, results in persistent or significant disability, is a congenital anomaly, or is otherwise medically important according to the investigator’s judgment. Seriousness determination drives expedited reporting obligations.

What triggers a 7-day versus a 15-day expedited reporting timeline?
In clinical trials, fatal or life-threatening unexpected serious adverse reactions require expedited reporting within 7 calendar days of the sponsor becoming aware of the case. All other serious unexpected adverse reactions from clinical trials require reporting within 15 calendar days. In post-marketing, all serious unexpected adverse drug reactions generally require reporting within 15 calendar days, though some jurisdictions require expedited reporting for specific serious expected reactions that exceed a threshold frequency. Confirm jurisdiction-specific timelines as these details vary between FDA, EMA, and other national authorities.

When is a PSUR or PBRER required?
EU marketing authorisation holders must submit PSURs for all authorised products at frequencies defined in the marketing authorisation decision or by the EMA PSUR single assessment schedule. PSURs are typically required annually for the first two years post-authorisation, every three years thereafter, and then on request. In the US, annual NDA and BLA safety reports serve a similar purpose under 21 CFR 314.81, and PBRERs may be requested by FDA for specific products. ICH E2C(R2) PBRER format is the harmonised standard across major ICH regions.

Does pharmacovigilance apply to investigational products in clinical trials?
Yes. Development-phase pharmacovigilance is governed by ICH E2A (expedited reporting of SUSARs) and each participating country’s national clinical trial regulations. Sponsors have specific obligations for Suspected Unexpected Serious Adverse Reactions (SUSARs) in clinical trials, including reporting to competent authorities and ethics committees. The Development Safety Update Report (DSUR), defined in ICH E2F, is the periodic safety report for investigational products and must be submitted annually to all regulatory authorities and ethics committees overseeing the trials.

Government and Regulatory Sources

Related VelSafe Articles

Building a PV Programme That Protects Patients and Survives Inspections

Pharmacovigilance is the system through which the safety of marketed medicines is continuously monitored and managed. The ICH guidelines, EMA GVP modules, and FDA regulations define the requirements; the practical work of building and operating the system is what determines whether those requirements are met. A PV programme that collects cases promptly, submits them on time, detects signals proactively, and maintains an inspection-ready quality system is not an aspirational goal: it is the operational standard that patient safety and regulatory compliance both require. Find more pharmaceutical compliance resources at velsafe.com.

Add a Comment

Your email address will not be published. Required fields are marked *