Pharmacovigilance

Pharmacovigilance System Requirements: What an MAH Actually Needs

A marketing authorization is not a one-time event. The day a product is approved, the company holding that approval takes on an ongoing obligation to keep watching what the product does in the real world, for as long as it stays on the market. That obligation is pharmacovigilance, and it comes with a specific set of things that have to exist, not just be described in a policy document somewhere.

We see this most often from the systems side: complaint intake forms that quietly double as adverse event reports, safety databases that need to talk to quality systems, and audit findings that trace back to a gap between what the PSMF says and what the team is actually doing. This is a walk through what an MAH's PV system needs, piece by piece.

What a marketing authorization holder's PV system actually needs

Strip away the acronyms and a functioning PV system needs to do five things reliably: take in every adverse event report regardless of source, decide quickly whether each one is serious and whether it was already known, watch the accumulating case data for new patterns, summarize the product's safety profile periodically for authorities, and keep a plan in place for managing known and potential risks. Everything else, the QPPV role, the PSMF, the databases, the SOPs, exists to make those five things happen consistently rather than depending on any one person's memory.

The QPPV and the PSMF

The Qualified Person for Pharmacovigilance is the named individual personally accountable for the safety system working. That accountability is deliberately personal rather than departmental, because a safety decision sometimes has to be made in hours, not after a committee meets, and someone has to be reachable and authorized to make it. A serious PV system also names a deputy, because the QPPV cannot be the single point of failure when they are unreachable.

The Pharmacovigilance System Master File describes how all of this actually works in practice: who the QPPV and deputy are, what SOPs govern case handling and signal management, what databases and vendors are involved, and a summary of the products the system covers. An inspector reading the PSMF should be able to understand the whole system from that one document, with references out to the detailed procedures rather than needing to hunt through them separately. A PSMF that describes a process nobody actually follows is worse than an honest gap, because it turns an inspection into a credibility problem rather than a corrective action.

ICSR collection and processing

An Individual Case Safety Report is the record of one adverse event tied to one patient and one product. Cases arrive from everywhere: a physician's spontaneous report, a patient calling a hotline, a clinical trial, scientific literature, and, very often, a customer complaint that was never framed as a safety report by the person who filed it. That last channel is the one companies most reliably underinvest in. A complaint that mentions an unexpected reaction has to reach the PV system, not just get logged and closed as a quality issue, which is why our complaints management module needs a clear handoff into PV intake rather than treating the two as unrelated workflows.

Assessing seriousness and expectedness

Once a case is in, someone medically qualified has to make two judgment calls quickly: is it serious, meaning it resulted in death, was life-threatening, required hospitalization, or caused significant disability, and is it expected, meaning it is already described in the product's reference safety information. Those two answers together determine how fast the case has to move and whether it triggers expedited reporting at all. Getting this assessment wrong in either direction has real consequences: too conservative and authorities get flooded with reports that dilute genuine signals; too lenient and a real safety issue gets buried in a routine periodic report months later than it should have surfaced.

Running this reliably is a case management problem as much as a medical one: every case needs a consistent workflow from intake through medical review to reporting, with the audit trail to prove each step happened on time, which is the kind of structured case processing our pharmacovigilance software is built to support.

Signal management

A signal is different from a single case. It is a pattern: a cluster of similar cases, an unexpected frequency compared with what is expected, or new information from a source outside the company's own case database, that suggests a possible causal relationship not previously known or fully characterized. Signal management is the ongoing work of screening the accumulating case data for those patterns, evaluating the ones that look real, and deciding whether they change the product's safety profile.

What makes signal management hard in practice is volume and consistency. A product with a large patient population generates a steady stream of cases, most of them unremarkable individually. Finding the pattern inside that stream requires the same case data to be coded and structured the same way every time, which is exactly what breaks down when case processing is inconsistent or spread across disconnected spreadsheets.

PSUR/PBRER and risk management plans

Periodically, independent of any single case, the company has to step back and summarize the product's cumulative safety experience: this is the Periodic Safety Update Report, now more formally the Periodic Benefit-Risk Evaluation Report under ICH E2C(R2), which weighs the accumulated safety data explicitly against the product's benefit. It draws on every ICSR received in the period, every signal evaluated, and any changes to how the risk is being managed.

The Risk Management Plan is the forward-looking counterpart: it documents what is already known about the product's safety profile, what remains uncertain, and what specific activities, from routine monitoring to additional studies, are in place to manage that risk. A PSUR/PBRER looks back at what happened; an RMP commits to what will be watched going forward. Neither one is a document you write from scratch each cycle. Both depend entirely on the case and signal data collected in between actually being complete and consistent.

Pharmacovigilance in Egypt

As general background: Egypt's national regulator, the Egyptian Drug Authority, operates a dedicated Egyptian Pharmaceutical Vigilance Center responsible for national safety monitoring, and Egyptian good vigilance practice guidance sets out how marketing authorization holders operating in Egypt are expected to structure their PV systems, broadly aligned with internationally recognized PV practice. We are not stating specific Egyptian reporting deadlines here beyond what is already established as general international practice: the widely referenced ICH E2D standard of expedited reporting for serious, unexpected ICSRs, commonly cited at 15 calendar days, with non-serious cases handled on a longer periodic cycle. Companies operating in Egypt should confirm current local timelines and procedural detail directly against the Egyptian Drug Authority's own published guidance rather than relying on the international reference points alone.

Frequently asked questions

Who is the QPPV and why does every marketing authorization holder need one?

The Qualified Person for Pharmacovigilance is the named individual personally accountable for the marketing authorization holder's safety system: for making sure adverse events are collected and assessed, signals are followed up, and reports reach authorities on time. Most jurisdictions that require a formal PV system require a named QPPV specifically because accountability needs to sit with a person, not just a department, when a safety decision has to be made quickly.

What is a PSMF and what does it need to contain?

The Pharmacovigilance System Master File is the master description of how a company's PV system actually works: the QPPV and their deputy arrangements, the standard operating procedures governing case handling and signal management, the databases used, the quality system around PV, and a summary of the products covered. Its job is to let an inspector understand and verify the whole system from one document, cross-referenced to the detailed procedures rather than repeating them in full.

What is the difference between an ICSR and a signal?

An ICSR, an Individual Case Safety Report, is the record of one adverse event associated with one patient. A signal is a pattern noticed across many cases, or across a case series and other data sources, suggesting a possible new causal relationship between a product and an adverse outcome that was not previously known or fully characterized. ICSRs are the raw material; signal management is the analysis that looks across all of them for something new.

What are PSUR and PBRER, and are they the same thing?

PSUR (Periodic Safety Update Report) and PBRER (Periodic Benefit-Risk Evaluation Report) refer to the same family of periodic aggregate safety report, with PBRER being the ICH E2C(R2) format that expanded the older PSUR concept to explicitly weigh cumulative safety data against benefit. In practice the terms are often used interchangeably, and which exact format and frequency applies depends on the receiving authority and the product's approval status.

What are the standard timelines for reporting a serious adverse event?

The internationally recognized standard, set out in ICH E2D and reflected in frameworks such as EU GVP Module VI, is expedited reporting of serious, unexpected ICSRs within 15 calendar days of the marketing authorization holder becoming aware of the case, with non-serious cases typically handled on a longer cycle, commonly referenced as 90 days. Exact deadlines and which cases qualify for expedited handling are set by each receiving authority's own regulation, so the 15-day and 90-day figures should be treated as the widely used ICH/EU GVP reference points rather than a universal rule.

CORPEX Informatics

Enterprise software solutions for pharmaceutical, food, chemical, and manufacturing industries. Headquartered in Egypt, serving regulated industries across the MENA region since 2006.

Is your PV system holding up under real case volume?

See how InFlow-PV handles case reception through medical review and reporting in one auditable workflow.

See InFlow-PV Pharmacovigilance