Pharmacovigilance India 2027
← Blog

The QPPV's Guide to PSMF Audits and Inspection Readiness in 2027

The QPPV's Guide to PSMF Audits and Inspection Readiness in 2027

Open pharmacovigilance compliance binder with PSMF, audit and SOP documents on a desk

For a QPPV, inspection readiness is not a document-production exercise that begins when an inspector sends a notice. It is the result of a pharmacovigilance system that is current, understood and supported by evidence.

In 2027, teams operating across India and the EU must keep local reporting procedures aligned with applicable national requirements while maintaining a clear view of the EU system. This guide focuses on practical qppv responsibilities: maintaining the Pharmacovigilance System Master File (PSMF), overseeing outsourced activities, preparing for audits and inspections, and ensuring that safety commitments are traceable.

What the PSMF must show

The PSMF should accurately describe the pharmacovigilance system in operation, not an idealised version of it. Under EU requirements and GVP Module II, it includes information about:

  • The QPPV, their responsibilities and back-up arrangements.
  • The MAH’s organisational structure and relevant internal and external sites.
  • Sources of safety data and how reports move through the system.
  • Computerised systems and databases, including their purpose and fitness for use.
  • Pharmacovigilance processes, quality procedures, training, performance monitoring and audits.
  • Products covered by the system, delegated activities, audit information and a change log.

Annexes often contain information that changes frequently, such as product and procedure lists, agreements, audit schedules and performance data. Keep them controlled and linked to the relevant source records. Check that the PSMF location and QPPV details in the applicable EU database remain accurate after changes.

Practical takeaway: Assign an owner and update trigger to each PSMF section and annex. Reconcile the file against controlled records after organisational, product, system or vendor changes.

PSMF index, controlled document register and version-controlled SOPs arranged on a desk

Immediate availability and change control

Commission Implementing Regulation (EU) 2025/1466 generally applies from 12 February 2026. GVP Module III Revision 2 became effective on 10 September 2026. Together, the updated EU framework reinforces that the PSMF must be permanently available to the QPPV and permanently and immediately available to inspectors at the site where it is kept. The earlier expectation of providing an electronic file within seven calendar days is not a sound operational inspection-readiness plan.

The PSMF does not need to be physically held at every company or vendor site. But the registered location must be clear, staff must know how to access the current controlled version, and system permissions must work. Test retrieval of the file and relevant annexes without relying on one individual’s account or a third party’s goodwill.

Maintain a logbook showing changes, dates and responsible persons. Keep superseded information and supporting records accessible in line with document-control and retention procedures. The PSMF audit annex should include the required audit information, including a rolling five-year view of completed audits and schedules.

Practical takeaway: Test access from the PSMF location. Record the test, access route, document version and any corrective action.

Risk-based inspections and a separate audit programme

Under revised Module III, EU routine inspection planning uses a risk-based approach. As a general approach for centrally authorised products, an inspection should take place within four years of the MAH’s first marketing authorisation, followed by a four-year cycle. The cycle may be shortened or lengthened based on ongoing risk assessment. This is an authority inspection-planning approach, not a fixed internal audit interval for every company.

Authorities may consider previous findings, safety concerns, product exposure, changes in the QPPV or database, the number of subcontractors, changes to contracts and the scope of outsourced activities. For-cause inspections can arise separately, including from reporting delays, concerns about RMP commitments or overdue corrective actions.

Internal audits are different. Plan them through a documented, risk-based programme, prioritising activities and vendors according to their impact on compliance and patient safety. Do not treat a routine inspection cycle as permission to defer an audit of a high-risk process.

Practical takeaway: Maintain two linked but separate schedules: the organisation’s risk-based PV audit programme and its inspection-readiness plan.

Printed risk matrix, audit schedule and deviation log beside a pharmacovigilance quality binder

QPPV oversight of subcontracted activities

Outsourcing does not remove the MAH’s responsibility for its pharmacovigilance system. The PSMF should describe delegated activities, the organisations performing them and the relevant sites. Written agreements should make responsibilities clear, including reporting routes, timelines, access to records, quality oversight, escalation and cooperation with inspections.

The revised EU inspection guidance makes the possibility of inspection at subcontracted third parties explicit, including further subcontractors. The QPPV therefore needs more than a contract register. They need oversight evidence: vendor performance measures, deviations, audit findings, escalations, CAPA follow-up and confirmation that safety information reaches the MAH in time.

Practical takeaway: For each significant vendor, keep a current activity map, agreement, performance review, audit history and open-action log. Test the escalation route with the vendor before an inspection does.

Accountability, authority and reporting lines

The QPPV must be able to oversee the system effectively, access relevant safety information and raise concerns. The PSMF should describe the QPPV’s role and authority, including how they can promote, maintain and improve compliance. The QPPV should be informed of material system changes, significant deviations, audit and inspection findings, and relevant CAPA.

The MAH retains ultimate responsibility for meeting its legal obligations. That does not make the QPPV’s oversight role nominal. A reporting line that leaves the QPPV unable to escalate material safety or compliance concerns is a practical weakness. Document how the QPPV communicates with senior management, how urgent concerns are raised, and how decisions and follow-up are recorded.

Practical takeaway: Review whether the QPPV can access metrics, audits, deviations, safety-system records and senior decision-makers. Record and escalate any gap.

RMP obligations and common findings

A risk management plan (RMP) is not just a regulatory submission. Its safety concerns, pharmacovigilance activities and risk-minimisation measures must connect to operational processes. Inspectors may examine whether required measures were implemented, whether commitments are on track, and whether new safety information led to appropriate assessment and action.

Common inspection weaknesses include an outdated PSMF, incomplete product or vendor lists, SOPs that do not match actual practice, missing training evidence, unexplained reporting delays, weak deviation investigations and CAPA that is closed without checking effectiveness. RMP commitments can also become disconnected from tracking systems, leaving overdue actions or inconsistent records.

Practical takeaway: Cross-check each applicable RMP commitment against an owner, due date, evidence of implementation and status report. Investigate discrepancies rather than simply updating the tracker.

Documentation, training and inspection practice

Records should allow another person to reconstruct what happened, when, under which procedure and with what outcome. Apply the correct retention schedule to each record type; do not assume that one period covers case records, audit files, PSMF versions, training records and contracts alike. Keep records legible, retrievable and protected from unauthorised change.

Before an inspection, test whether staff can explain their role and show the records that support it. Training files should show completion against current procedures and role requirements. SOPs should be approved, effective and consistent with the work being performed. Deviation logs should include assessment, impact, investigation, CAPA, ownership and closure evidence.

Practical takeaway: Run a mock inspection using realistic requests: retrieve a case record, show the applicable SOP version, trace a deviation to CAPA, and produce current training and vendor records.

India: align CDSCO and PvPI processes with EU controls

For companies operating in India and the EU, a global process should not obscure local obligations. Maintain a controlled India reporting procedure that identifies applicable CDSCO and PvPI requirements, report routing, timelines, responsibilities and evidence of submission. Verify the current guidance version used by your organisation and update the procedure when official requirements change.

The Indian Pharmacopoeia Commission has announced the ADR-PvPI 2.0 app as a reporting channel, with features that include reporting for medicines, vaccines and medical devices. It supports collection of additional information and attachments. The app does not replace the MAH’s need to follow its applicable regulatory reporting obligations. Review the IPC announcement, the CDSCO suspected ADR reporting form, and relevant CDSCO pharmacovigilance guidelines when reviewing local procedures.

Practical takeaway: Keep an India-specific reporting matrix and reconcile it with global case-processing procedures. Record the source and version of each regulatory requirement.

Inspection-readiness checklist for 2027

Use this checklist as a starting point for your next review:

  1. Confirm the PSMF location, current version and immediate access at the stated site.
  2. Check QPPV contact details, authority, back-up arrangements and escalation routes.
  3. Reconcile the PSMF’s product, site, vendor, system and SOP lists against controlled records.
  4. Review audit schedules, findings, deviations and CAPA for overdue or ineffective actions.
  5. Confirm training records are current and role-appropriate.
  6. Verify vendor agreements, inspection cooperation and subcontractor oversight.
  7. Trace RMP measures and commitments to implementation evidence and accountable owners.
  8. Test India reporting workflows and confirm the applicable CDSCO/PvPI guidance version.
  9. Conduct a mock inspection and record gaps, owners and due dates for remediation.

Practical takeaway: Treat checklist gaps as tracked quality actions, not informal observations. Confirm completion and effectiveness.

Continue the discussion in Chennai

Pharmacovigilance India 2027 takes place on 29 July 2027 in Chennai. The one-day conference includes a dedicated inspection-readiness session on PSMF, audits and lessons from recent MHRA and FDA inspections, alongside sessions on PvPI and CDSCO, signal management, AI in case processing and outsourcing partnerships.

View conference information and programme, review ticket options, or explore sponsorship opportunities.