Most pharmacovigilance teams prepare for audits by reviewing their SOPs, tidying up training records, and making sure submission timelines are documented. What they frequently underestimate is how methodically an auditor or GPvP inspector will move through the entire case processing workflow, from the moment a report arrives to the point of regulatory submission, looking not just for whether cases were submitted on time but for whether the system that produced those submissions was functioning as it should at every step in between.
The MHRA has been conducting Good Pharmacovigilance Practice (GPvP) inspections since 2003. Recent EMA and MHRA pharmacovigilance inspection data shows that approximately 28 to 32% of major PV findings stem from weaknesses in system governance, documentation accuracy, and oversight continuity rather than errors in individual case processing. That figure matters because it means a significant proportion of findings are not about missed deadlines or wrong MedDRA codes. They are about whether the system governing how those decisions were made can be demonstrated to have worked consistently and under control.
This blog sets out what auditors actually focus on when they review your case processing workflow, area by area, so that preparation is targeted at what is actually being evaluated.
Case Intake and Valid Case Determination
The first thing an auditor will test is where cases come from and how they are captured. Adverse event reports arrive through multiple channels:
- Spontaneous reports from healthcare professionals and patients
- Reports from clinical trials and non-interventional studies
- Literature surveillance outputs
- Reports from contractual partners, distributors, and licensees via Safety Data Exchange Agreements
- Social media and digital monitoring where applicable
- Regulatory authority communications
An auditor will want to see documented evidence that all of these intake channels are actively managed, not just theoretically covered in an SOP. They will check whether:
- Each intake channel has a defined owner and documented receipt process
- Reports received through partner channels are being captured within the agreed contractual timelines
- A duplicate search is consistently performed before a new case is opened
- Cases that arrive incomplete are formally logged and tracked rather than informally held pending additional information
- The clock start date is consistently and correctly identified as the date the first valid information was received by anyone in the organisation, not the date it reached the PV team
The clock start is one of the most consistently cited audit findings in case processing. Organisations that define receipt as the date the PV database was updated rather than the date the report first reached any company employee will be cited, because the regulatory clock runs from first receipt regardless of internal routing.
Triage And Seriousness Assessment
After intake, the auditor will examine how cases are triaged. This is where many organisations have gaps that are invisible during routine operations but become visible under scrutiny. The auditor will look at:
- Whether triage is conducted against a documented set of criteria aligned with ICH E2A seriousness definitions: death, life-threatening, hospitalisation or prolonged hospitalisation, persistent or significant disability, congenital anomaly, and other medically important events
- Whether seriousness determinations are made by appropriately trained and qualified staff
- Whether there is documented evidence of the seriousness assessment decision for each case, including the rationale for cases where the initial assessment was non-serious
- Whether cases initially classified as non-serious were upgraded when follow-up information was received, and whether the clock was correctly restarted from the date the upgrade-triggering information arrived
- Whether cases involving pregnancy, medication error, overdose, misuse, or off-label use are consistently identified and handled under the correct reporting category
A common finding at audit is inconsistent seriousness assessment across cases of the same event type. Two cases with identical reported events classified differently, with no documented rationale for the distinction, signals to an auditor that triage is being conducted individually rather than against a consistently applied standard.
Meddra Coding And Data Entry Quality
MedDRA coding is the step most frequently scrutinised for technical accuracy, and it is also the area where training record gaps cause the most problems. An auditor reviewing coding will check:
- Whether the most specific and clinically appropriate Preferred Term has been selected rather than a higher-level term used as a shortcut
- Whether the Lowest Level Term used to reach the Preferred Term is documented and justified
- Whether the same event is being coded consistently across similar cases or whether different coders have applied different Preferred Terms to the same clinical scenario
- Whether the version of MedDRA in use is current and whether there is a documented process for updating coding when new MedDRA versions are released
- Whether WHODrug coding for suspect and concomitant medications is applied consistently and at the correct level of specificity
Data entry quality more broadly will also be reviewed:
- Whether mandatory fields in the safety database are consistently populated
- Whether free-text fields contain medically accurate information that matches the source document
- Whether the source document itself has been retained and is accessible for audit trail review
- Whether any data corrections or amendments are made through the validated amendment process with a documented reason, rather than by overwriting original entries
Narrative Writing And Medical Review
The case narrative is reviewed by auditors because it represents the organisation’s clinical interpretation of the case. A poor narrative does not just reflect weak writing skills. It raises questions about whether medical review is genuinely happening. Auditors will check that narratives:
- Tell a coherent chronological story of the adverse event including patient demographics, medical history, concomitant medications, event onset, course, and outcome
- Accurately reflect all information in the source document without omitting clinically relevant detail
- Do not simply reproduce the raw data fields from the database without synthesis
- Are written by or reviewed by a medically qualified person where the case is serious
- Include causality assessment with a documented rationale, referencing the Reference Safety Information where expectedness is also assessed
- Are updated when follow-up information is received, with version history maintained in the audit trail
A finding that is increasingly common following recent MHRA guidance published in June 2026 on AI-generated inspection responses is the use of AI tools to generate narratives without evidence of genuine medical oversight. Auditors and inspectors are now specifically checking whether narratives reflect real clinical judgement or formulaic AI-generated text that passes a completeness check but lacks medical depth.
Quality Control And Qc Checks
The QC step is where most organisations believe their process is strongest, because it is the most formally documented. An auditor will test whether QC is genuinely adding value or whether it has become a sign-off step rather than a substantive review. They will look for:
- A documented QC checklist with specific criteria that are checked against each case
- Evidence that QC findings are recorded, trended, and used to identify recurring processing errors
- QC error rates by case processor, event type, or source channel to demonstrate active quality monitoring
- Escalation procedures for cases where QC identifies a seriousness or coding error that changes the expedited reporting classification
- Whether QC of follow-up cases checks that the follow-up information has been incorporated correctly and that the submission clock has been recalculated where required
An auditor who finds QC records showing a consistent pass rate of 100% across all processors and case types will treat that as a red flag rather than a reassurance. It typically indicates that QC is not being conducted at a level of scrutiny that would identify errors when they occur.
Submission Timeliness And Regulatory Reporting Compliance
The submission record is where auditors spend significant time and where expedited reporting failures generate the most serious findings. Under GVP Module VI, serious unexpected adverse drug reactions must be submitted to the relevant regulatory authority within 15 calendar days for post-authorisation cases, and within 7 calendar days for fatal or life-threatening unexpected cases in clinical trials. Auditors will review:
- A submission compliance metric covering the period under audit, showing on-time submission rates by case type, seriousness category, and market
- Cases submitted late, with a documented root cause and CAPA for each identified delay pattern
- Whether follow-up reports were submitted within the same timelines calculated from the date new information was received
- Whether acknowledgements from EudraVigilance, the MHRA Yellow Card system, or FAERS were received, reviewed, and actioned for error or rejection notifications
- Whether non-serious cases to EudraVigilance are being submitted within 90 days as required under the EU centralised submission requirements
- Whether there is a reconciliation process with Safety Data Exchange Agreement partners to confirm that all cases reportable under those agreements have been received and processed
Under the UK’s post-Brexit pharmacovigilance framework, the MHRA requires separate submissions and independent PV oversight structures including a dedicated UK Qualified Person for Pharmacovigilance (QPPV). Auditors inspecting UK MAHs will specifically check that UK-specific submissions are being handled separately from EU submissions and that the UK QPPV has documented oversight of the UK case processing and submission programme.
Training Records And Sop Currency
Training records are reviewed in parallel with every other workflow area because the auditor is verifying not just that a process exists but that the people performing it are documented as trained and competent against the current version of the relevant SOP. Common findings include:
- Staff performing case processing tasks without a training record linked to the current SOP version
- Training records completed but no evidence of assessed competence, only attendance
- SOPs that have not been reviewed within the required review cycle, leaving them formally superseded but still in use
- New staff performing live case processing before completing the required training curriculum
- The QPPV or deputy QPPV lacking documented training on current GVP modules and jurisdiction-specific requirements
An auditor will request the training matrix for the PV team and cross-reference it against the SOP version history. If a SOP was updated six months ago and half the case processing team has no training record against the new version, every case processed in that period by those staff members is potentially a finding.
How Quality Vigilance Ltd Supports Pharmacovigilance Audit Readiness
Pharmacovigilance case processing audits surface problems that are genuinely difficult to see from inside a functioning operation, because the workflow appears to be working right up until an auditor tests whether the documentation trail behind it is complete and coherent. Quality Vigilance Ltd works with MAHs, CROs, and PV service providers to prepare for and respond to GPvP audits and MHRA pharmacovigilance inspections through:
- Conducting mock GPvP audits that test the full case processing workflow from intake through submission, replicating the depth and scrutiny of an MHRA or EMA inspection
- Reviewing and rewriting case processing SOPs to align with current GVP Module VI expectations, MHRA post-Brexit requirements, and ICH E2B(R3) submission standards
- Auditing a sample of processed cases for narrative quality, MedDRA coding accuracy, seriousness and expectedness determination, clock start consistency, and QC documentation completeness
- Reviewing submission compliance metrics and identifying root causes for any timeliness failures, including drafting the CAPA documentation required to close findings
- Assessing Safety Data Exchange Agreements and partner reconciliation processes for completeness, currency, and actual operational adherence
- Building training matrices that link role-specific PV responsibilities to documented competency records, ensuring the evidence trail holds up when an auditor cross-references training against SOP version history
- Supporting live inspection responses and post-inspection CAPA development where GPvP findings have been received from the MHRA’s IAG2 team
Visit qualityvigilance.com or contact the team at [email protected] to discuss your pharmacovigilance audit readiness position.