A quality and pharmacovigilance due diligence audit evaluates a target company’s GMP, GDP, and PV compliance posture before an acquisition, licensing deal, or investment closes, surfacing regulatory risks that don’t always show up in financial or legal due diligence alone. For pharma M&A specifically, undiscovered compliance gaps can translate directly into post-acquisition liability, remediation costs, or even product recalls, which is why acquirers increasingly bring in specialist quality and PV consultants alongside their financial and legal advisors rather than treating compliance as a box-ticking afterthought.
Why Standard Due Diligence Misses Compliance Risk
Most M&A due diligence processes are built around financial, legal, and commercial review. Accountants check the books, lawyers review contracts and IP, and commercial teams assess market position. Quality and regulatory compliance often gets a much lighter touch, sometimes limited to a checklist of “do you hold the relevant licences” rather than a genuine assessment of whether the underlying quality system actually functions.
This gap matters more in pharma than in almost any other sector, and a few examples make the risk concrete:
- A manufacturing site with an unresolved GMP finding that doesn’t appear as a red flag in financial statements
- A pharmacovigilance system with under-resourced signal detection, running compliant on paper but not functioning as intended day to day
- A QPPV function that exists on paper but isn’t genuinely operational, often outsourced with minimal real oversight
None of these show up cleanly on a balance sheet. They tend to surface roughly eighteen months after close, when an inspection uncovers exactly what a proper pre-acquisition audit would have flagged. By then, the acquirer owns the problem entirely, along with whatever remediation costs, regulatory scrutiny, or reputational damage come with it.
The other thing standard due diligence tends to miss is cultural and systemic risk, not just individual findings, but whether the target’s quality organization has the maturity to sustain compliance as it scales, integrates, or gets absorbed into a new corporate structure. A target might look compliant on paper today while running on a handful of overstretched staff whose departure post-acquisition would quietly collapse the whole system.
What a Quality and PV Due Diligence Audit Actually Covers
A well-scoped pre-acquisition audit typically looks across several distinct areas, each carrying its own risk profile:
- GMP compliance status, including recent inspection history, open CAPAs, Form 483s or Warning Letters, and the general maturity of the manufacturing quality system
- GDP and supply chain compliance, covering distribution licensing, Responsible Person arrangements, and the robustness of cold chain and storage controls where relevant
- Pharmacovigilance system maturity, including whether the QPPV function is genuinely operational, how ICSR processing and timelines are tracked, and whether signal detection is happening in practice rather than existing only in an SOP
- Regulatory licence status, verifying that Marketing Authorisations, manufacturing licences, and wholesale distribution licences are current, correctly scoped, and free of pending regulatory action
- QMS documentation quality, assessing whether SOPs, deviation records, and training documentation reflect a system that’s actually followed, versus one that exists mainly for audit purposes
- Vendor and supplier oversight, since a target’s own compliance can be undermined by weak oversight of its CMOs, API suppliers, or distribution partners
- Data integrity practices, particularly around electronic systems, audit trails, and whether historical data can withstand scrutiny if challenged
- Key personnel dependency risk, identifying whether compliance functions rely disproportionately on one or two individuals whose departure would materially weaken the system
Each of these areas gets assessed not just for current compliance status, but for the underlying risk of future non-compliance, which is often the more important question for an acquirer trying to price risk into a deal.
How Due Diligence Audits Differ From Routine Compliance Audits
It’s worth being clear about what makes an M&A due diligence audit a genuinely different exercise from a routine supplier or internal audit, because the differences shape how it needs to be run:
- Timeline pressure is far tighter. Deal timelines are often measured in weeks, not months, so the audit needs to deliver a clear risk picture quickly without cutting corners on the areas that matter most.
- Confidentiality requirements are stricter. Target companies are often unaware of, or only partially aware of, the reason for the audit, requiring careful handling of access, documentation requests, and communication with target staff.
- The output feeds directly into deal terms, not just a CAPA plan. Findings may influence valuation, indemnification clauses, or specific closing conditions, so the reporting needs to be structured in a way that’s useful to lawyers and deal teams, not just quality professionals.
- Risk framing matters as much as findings. A due diligence report needs to communicate not just what’s wrong, but the likely cost, timeline, and complexity of fixing it, since that’s what actually informs a negotiation.
- Access is often limited or staged. Unlike a routine audit where full cooperation is a given, M&A due diligence sometimes happens under restricted access agreements, particularly pre-signing, which changes what can realistically be assessed at each stage.
- The auditor needs commercial fluency, not just technical expertise. Findings need to translate into language a CFO or deal lead can act on, connecting a compliance gap to a tangible financial or timeline implication.
Common Red Flags That Surface During PV and Quality Due Diligence
Having conducted these audits across a range of deal types, certain patterns come up often enough to be worth watching for specifically:
- A QPPV role that exists in name but lacks real operational involvement, often outsourced to a freelancer with minimal actual oversight of the safety system
- ICSR backlogs or missed regulatory reporting timelines that aren’t visible until someone actually pulls the underlying case tracking data
- CAPAs that are closed on paper but show no evidence of effectiveness verification, a strong signal of a system optimized for passing audits rather than genuinely preventing recurrence
- Heavy reliance on a single individual for QP, RP, or QPPV functions, with no deputy or succession plan, creating a fragile compliance structure
- Manufacturing or distribution agreements with CMOs or logistics partners that lack proper quality agreements, leaving oversight gaps that only surface under scrutiny
- Inconsistent data across systems, where safety database records, regulatory submissions, and internal tracking don’t fully align, often a sign of manual, error-prone processes
- Recent inspection findings that were formally closed but with remediation that looks superficial on closer inspection
None of these are necessarily deal-breakers on their own. What matters is whether they’re isolated issues or symptoms of a broader systemic weakness, and whether the cost and complexity of fixing them is something the acquirer has genuinely priced in.
How the Findings Shape Deal Structure and Negotiation
The value of a quality and PV due diligence audit isn’t just in identifying problems, it’s in giving the acquiring party leverage and clarity going into negotiation. Findings from this kind of audit typically feed into a deal in a few concrete ways.
They can inform valuation adjustments, where the estimated cost of remediating identified gaps is factored directly into the purchase price. They can shape indemnification and escrow terms, ensuring the seller retains some financial responsibility for pre-existing compliance issues that surface after close. They can also influence closing conditions, in some cases requiring specific remediation steps, such as resolving an open regulatory finding, before the deal can complete. And in some cases, they simply give the acquiring team the information needed to plan post-acquisition integration realistically, budgeting for the quality and PV investment that will actually be needed rather than assuming the target’s existing system can be absorbed as-is.
Without this kind of audit, acquirers are often negotiating and closing deals with a materially incomplete picture of what they’re actually taking on, which tends to surface as unpleasant surprises well after the deal is done and there’s far less leverage to address them.
Post-Acquisition: Where Due Diligence Findings Lead Next
A due diligence audit doesn’t end its usefulness at signing. The findings typically become the foundation for a post-acquisition integration plan, prioritizing which compliance gaps need immediate attention versus which can be addressed on a longer timeline. This might include stabilizing a fragile QPPV or QP arrangement quickly, addressing an open CAPA backlog before it attracts regulatory attention, or harmonizing the target’s quality system with the acquirer’s own standards and procedures.
Companies that treat the due diligence report as a living integration roadmap, rather than a document that gets filed away once the deal closes, tend to see a much smoother transition and avoid the scenario where a known but unaddressed issue eventually becomes an inspection finding under the new ownership.
Frequently Asked Questions
When in the M&A process should a quality and PV due diligence audit happen?
Ideally early enough to inform deal terms and valuation, typically running in parallel with financial and legal due diligence, though the depth of access may increase in stages as the deal progresses toward signing.
How long does a pharma quality and PV due diligence audit take?
This depends heavily on deal timeline and target complexity, but these audits are generally designed to be completed within a tighter window than a routine compliance audit, often a few weeks, to align with typical deal schedules.
Can due diligence audits be conducted without the target company’s full knowledge of the reason?
In many cases, yes, particularly in early deal stages, though this requires careful coordination with legal counsel and deal teams to manage confidentiality and access appropriately.
Do due diligence audits cover every product and site in a target’s portfolio?
Not always. Scope is usually risk-based, prioritizing the sites, products, and functions most material to the deal rather than attempting an exhaustive review of everything, particularly under tight deal timelines.
Is a quality and PV due diligence audit necessary for smaller licensing deals, not just full acquisitions?
Yes, though the scope is typically smaller. Licensing and co-marketing arrangements still transfer real regulatory risk, particularly around pharmacovigilance obligations, so a scaled-down due diligence review is generally worthwhile even for smaller transactions.
How Quality and Vigilance Ltd Can Help
If you’re evaluating a pharma acquisition or licensing deal and need to hire a pharma due diligence consultant, Quality and Vigilance Ltd provides quality and pharmacovigilance risk assessment services designed to fit tight deal timelines without compromising on the depth of review. As an experienced M&A compliance audit provider, we help acquirers see past the paperwork to understand the real operational risk they’re taking on.
- Risk-based GMP, GDP, and pharmacovigilance due diligence audits scoped to deal timelines
- Clear, deal-ready reporting that translates compliance findings into commercial and financial implications
- Support identifying remediation costs and timelines to inform valuation and negotiation
- Post-acquisition integration planning based on due diligence findings
- Confidential engagement models suited to sensitive, pre-signing deal stages
If you need due diligence support for a pharma acquisition or licensing deal, get in touch with Quality and Vigilance Ltd to discuss your transaction timeline and requirements.