Good pharmacovigilance practices guidelines (GUI-0102): Pharmacovigilance system

On this page

Guiding principles

You are responsible for meeting the requirements outlined in the act and regulations and clarified in our guidance documents. You will also need the help and commitment of your partners and personnel at all levels.

To meet these requirements, you need a robust pharmacovigilance system as it forms an integral part of Good Pharmacovigilance Practices (GVP).

With a robust system, you can:

To build a robust pharmacovigilance system, you should:

Written procedures

Overall considerations

You should prepare and document written procedures outlining pharmacovigilance processes with step-by-step instructions for relevant personnel and departments. These procedures should have unique identifiers.

Periodic reviews, as per established timelines, ensure that the written procedures continue to adhere to current regulations, expectations, and accurately reflect current practices. The revision history, reason(s) for revision, revision number, and effective dates for written procedures should be documented accordingly.

Designated personnel should date, approve, and sign any revisions to the procedures (Refer to the Personnel and training section). All personnel and departments involved in pharmacovigilance should know when a procedure is revised and be trained before a revised procedure takes effect.

When pharmacovigilance activities are contracted to a third party, you must ensure that roles and responsibilities, as well as step-by-step instructions are clearly documented in the respective written procedures or contractual agreements. They should be easy to follow to allow contractors to comply with the applicable regulatory requirements (Refer to the Contractual agreements section). Copies of procedures belonging to a third party and contractual agreements should be made available during inspections/audits.

Documentation should show that the procedures have been put into practice.

Deviations

A deviation is a change or departure from the steps and/or instructions outlined in an approved written procedure. These can be planned or unplanned.

In a planned deviation, the departure should be documented, evaluated and approved before the change is implemented.

In an unplanned deviation, the departure is unexpected and could suggest a systematic deficiency which needs to be resolved.  

A systematic deficiency is a fundamental inadequacy that exists within the processes or mechanisms of a pharmacovigilance system. It can arise from inadequate planning, design, or oversight of the system. This deficiency impacts the system’s ability to function effectively, consistently, and achieve its intended goal. It is widespread instead of isolated. A widespread incident is one that is part of a series or pattern of similar occurrences.

When there is an unplanned deviation, you should:

Good quality control practices should be in place to detect deviations. You may periodically perform:

Periodic review of trends, performance, and processes will inform continual process improvements that are necessary to enable compliance and maintain a state of control.

Change control

Establish a change control system to allow ongoing process optimization and a continuing state of control. The department responsible for the change should document, evaluate the impact, and approve all changes, as well as identify the appropriate effective date. Any significant change that impacts compliance of your pharmacovigilance responsibilities may require re-validation or verification of systems or processes.

Business continuity plan

Overall considerations

You should establish a risk-based business continuity plan, which can be implemented to enable you to continue critical operations during scenarios such as:

Merging or migrating databases

When merging or migrating pharmacovigilance databases, you should consider the following:

Audits

Audits (previously known as self-inspection) help you monitor your organization’s compliance, including the compliance of third-party vendors that you delegate responsibilities to. Your contractual agreements should outline your right and responsibility to conduct periodic audits on third-party vendors according to your risk-based strategy.

Scope

The scope of your audit program should cover all departments or third parties that take part in your pharmacovigilance activities, for example, those that:

Overall considerations

Your audit program should include:

Validation of computerized systems

There should be an assessment to determine if adequate validation has been completed on an electronic system used to capture, process, manage or archive pharmacovigilance activities. Adequacy should be assessed based on the criticality of the system and its intended use. Validation confirms that the system is reliable, credible and will perform as expected. You should document how validation, testing, and re-validation is to be conducted.

Validation reports should be produced to document the results of the validation tests you performed. The results should clearly indicate that the system can be used as intended and is performing as specified.

Modifications or additions made to the electronic system, such as software upgrades or data migration, can affect performance. These can, in turn, affect the quality of the validated applications, and thus the integrity of electronic information. The system’s reliability can also be questioned.

For these reasons, you should assess and approve all changes, using your change control system, to hardware or software used in pharmacovigilance activities. This assessment will also help determine if re-validation is needed and the scope of re-validation.

When conducting a risk-assessment regarding the validation of a computerized system, including when there is a change to the system, ask yourself the following questions such as:

Personnel and training

Overall considerations

Employees, in-house or contracted, involved in pharmacovigilance activities are to be qualified and trained on the Canadian requirements that are relevant to their specific responsibilities. This applies to employees such as those who:

Qualified alternate(s) should be identified to carry out duties when responsible personnel is/are absent.

You should ensure that employees:

You should maintain records for in-house and contracted personnel such as:

Designated person to oversee pharmacovigilance activities

In addition to the above overall considerations, you should identify a person designated to lead and oversee all pharmacovigilance activities to ensure that all requirements are met. You should also designate an alternative person with the required experience to act in the absence of this designated person. This designated person can either be the same individual or a different individual than the qualified healthcare professional.  

Qualified healthcare professional

The qualified healthcare professional (QHCP) is a medically-qualified person such as a physician, dentist, pharmacist, nurse, coroner, or an individual with appropriate healthcare education and therapeutic expertise.

The QHCP should be involved in or oversee key pharmacovigilance activities such as:

There may be delegation of certain operational activities. The risk-based strategy and process on delegation of these key activities should be justified and documented to enable meaningful collection and assessment of safety information and compliance.  

Contractual agreements

Delegation of pharmacovigilance activities

You may delegate a pharmacovigilance activity to a third party. However, if you do, you continue to be ultimately responsible for meeting all regulatory requirements and principles of GVP described in this guidance document. You must ensure processes are in place to control outsourced activities.

You should have a written agreement that is signed and dated between your organization and the third party.

At minimum, a contractual agreement should exist between the MAH and the following parties:

Elements of a contractual agreement on pharmacovigilance activities

Your contractual agreement or its annex, where applicable, should include the following, at minimum:

Your contractual agreement or its annex should also consider the following, where relevant, according to the risk of impact on your pharmacovigilance system:

The agreement should be reviewed periodically to reflect current requirements and practices.

Cross-licensed product

Each party (licensor and licensee) is responsible for pharmacovigilance activities on its own DIN(s). When your drug is a cross-licensed product, your contractual agreement should ensure that proper communication takes place to enable you and your cross-licensed partner (between the licensor and licensee) to individually fulfill your responsibilities. For example:

Merger and acquisition

Compliance with requirements set out in the regulations and the GVP principles in this guidance document must continue during transition periods such as a merger, acquisition, or migration of pharmacovigilance databases. A contractual agreement should be in place to outline roles and responsibilities to ensure compliance. You must minimize any impact on ongoing pharmacovigilance activities.  

Please refer to the Business continuity plan, Validation of computerized systems, and Maintenance of records sections for further information regarding expectations during  transition periods.

Page details

2026-05-22