Pharmacovigilance audit checklist template: five words every QPPV and PV Quality Assurance professional should turn into a working tool rather than a box-ticking exercise. Auditing the pharmacovigilance system is not an optional good practice: it is a legal obligation for every marketing authorisation holder, with precise requirements on risk-based planning, finding grading and the recording of audit outcomes in the PSMF. In this guide you will find the up-to-date regulatory framework, the three planning levels required by GVP Module IV and a 12-point checklist template ready for your next internal audit or GVP inspection preparation.
Pharmacovigilance audit checklist template: the regulatory framework
The audit obligation stems from Article 104(2) of Directive 2001/83/EC: the marketing authorisation holder must perform regular audits of its pharmacovigilance system, place a note concerning the main findings in the PSMF and, based on those findings, ensure that an appropriate corrective action plan is prepared and implemented. Commission Implementing Regulation (EU) No 520/2012 turns this into quality-system requirements: Article 13 requires risk-based audits of the quality system at regular intervals and mandates that the dates and results of audits and follow-up audits be documented; Article 17 sets equivalent obligations for competent authorities and EMA.
The operational reference is EMA's GVP Module IV – Pharmacovigilance audits (Rev 1), to be read together with Module I on quality systems. Watch the evolving framework: Commission Implementing Regulation (EU) 2025/1466, adopted on 22 July 2025, amends Regulation 520/2012 and, among other things, strengthens the documentation of delegated activities and the oversight of PV service providers, with EMA progressively updating the GVP modules to reflect it. If you are revising your audit SOP today, factor it in now.
The risk-based approach: strategy, programme and plan
GVP Module IV does not ask for "an audit every now and then", but for a three-level planning pyramid, approved by upper management and driven by risk: probability and impact of process failures, criticality for patient safety, results of previous audits, organisational change.
| Level | Horizon | Document | Key content |
|---|---|---|---|
| Strategic | 2–5 years | Audit strategy | Coverage of all PV processes, affiliates, delegated activities and vendors; upper-management endorsement |
| Tactical | Annual | Audit programme | Risk-based selection of the areas to audit in the year: critical processes, key controls, high-risk areas |
| Operational | Individual audit | Audit plan | Documented scope, objectives, criteria, sampling and risk assessment for each engagement |
The same logic must extend to partners: CROs, distributors and service providers covered by an SDEA belong in the audit universe, with frequencies proportionate to risk. This is exactly where Regulation 2025/1466 raises the bar.
Topics like this one — GVP audits, PSMF, inspections and CAPA — are the bread and butter of The Pragmatic GMP, GuideGxP's free weekly newsletter: one GxP topic a week, explained from an operational angle, no fluff. Subscribe so you don't miss the next deep dives.
The 12-point pharmacovigilance audit checklist
Use this checklist as a self-assessment template before an internal audit or an inspection: every item must be backed by documented evidence you can retrieve quickly.
- Audit strategy and programme: do they exist, are they risk-based, management-approved and actually followed?
- Up-to-date SOPs: are all PV procedures (including audit and CAPA) reviewed, approved and trained out?
- Training records: are the training files of the QPPV, deputy and team complete and current?
- A "mirror" PSMF: does the PSMF reflect today's operational reality (org charts, SOP list, vendors) and has it been reviewed recently?
- PSMF annex: is the list of scheduled and completed audits present and current, with the notes on critical and major findings?
- Compliance KPIs: are the last 12 months of ICSR reporting metrics (e.g. the 15-day timeline for serious cases) and PSUR submission metrics ready to show?
- SDEAs and partners: a complete list of signed agreements, review dates and evidence of periodic case reconciliations?
- Vendor audits: have critical partners been audited per the programme, with their CAPAs tracked?
- CAPA status: are all corrective actions from audits, deviations and inspections tracked, with owners and deadlines met?
- Signal management: are recent signal detection reports available and is the process documented and proactive?
- Safety database validation: is the validation report (or its summary) available and consistent with Annex 11?
- Business continuity: is the back-up plan for the QPPV and the system (including disaster recovery) tested?
Grading findings: critical, major, minor
GVP Module IV requires every finding to be graded by relative risk. A critical finding is a fundamental weakness that adversely affects the whole pharmacovigilance system or the rights, safety or well-being of patients. A major finding is a significant weakness, detrimental to a whole process or potentially affecting patient safety. A minor finding is a weakness in part of a process, not expected to affect the system as a whole.
Grading is not an academic exercise: critical and major findings must be noted in the PSMF together with the related CAPA plan, and the note can only be removed once there is objective evidence that corrective actions have been fully implemented. A recurring inspection finding is precisely a PSMF that "forgets" the outcomes of internal audits.
From internal audit to GVP inspection
The internal audit is the dress rehearsal for the regulatory inspection (GVP Module III): EMA and national inspectors assess the same three pillars. First, the system: a complete PSMF matching operational practice. Second, the processes: ICSR management within timelines, documented signal detection, timely PSURs and risk minimisation measures actually implemented. Third, QPPV oversight: real authority over the system, involvement in key decisions and knowledge of what happens in affiliates and partners. The most frequent findings — an outdated PSMF, ICSR delays caused by weak partner data flows, missing reconciliation, gut-feeling signal detection — can all be caught by a well-built internal audit programme. If your audit finds them before the inspector, they are CAPAs; if the inspector finds them, they are findings.
GuideGxP recommendation
Treat the checklist as a living document: update it after every audit, inspection or regulatory change, and tie each item to concrete evidence (reports, logs, KPIs), not a self-declared "yes". Plan next year's audit programme in October–November, include at least one critical vendor, and use the critical/major/minor grading in internal audits too: get the team used to the inspector's language. Finally, check that your audit SOP still cites current requirements: with Regulation 2025/1466 and the ongoing GVP revisions, many procedures written in 2015 are due for an update.
To build an audit-proof PV system — GVP Modules I, II, III and IX, the PSMF, the role of the QPPV and their team — see GuideGxP's Guide to the Pharmacovigilance Manager (QPPV) and His Team: an operational guide with practical examples and an audit-ready structure.