Good pharmacovigilance practices guidelines (GUI-0102): Pharmacovigilance system
On this page
- Guiding principles
- Written procedures
- Business continuity plan
- Audits
- Validation of computerized systems
- Personnel and training
- Contractual agreements
Guiding principles
You are responsible for meeting the requirements outlined in the act and regulations and clarified in our guidance documents. You will also need the help and commitment of your partners and personnel at all levels.
To meet these requirements, you need a robust pharmacovigilance system as it forms an integral part of Good Pharmacovigilance Practices (GVP).
With a robust system, you can:
- monitor the safety and effectiveness of your drugs
- notify Heath Canada within the required timelines
- take reliable and timely actions based on the available evidence
To build a robust pharmacovigilance system, you should:
- set out a decision-making process with deliverables for consistency in all activities
- assign personnel who perform or oversee the deliverables
- ensure that responsibilities are well understood by internal and external parties
- ensure that an adequate number of qualified and trained personnel are available
- identify and evaluate performance indicators
- address any deficiencies in a timely manner
- carry out and monitor corrective and risk mitigation measures, as necessary
- document all activities to demonstrate that you met the deliverables
Written procedures
Overall considerations
You should prepare and document written procedures outlining pharmacovigilance processes with step-by-step instructions for relevant personnel and departments. These procedures should have unique identifiers.
Periodic reviews, as per established timelines, ensure that the written procedures continue to adhere to current regulations, expectations, and accurately reflect current practices. The revision history, reason(s) for revision, revision number, and effective dates for written procedures should be documented accordingly.
Designated personnel should date, approve, and sign any revisions to the procedures (Refer to the Personnel and training section). All personnel and departments involved in pharmacovigilance should know when a procedure is revised and be trained before a revised procedure takes effect.
When pharmacovigilance activities are contracted to a third party, you must ensure that roles and responsibilities, as well as step-by-step instructions are clearly documented in the respective written procedures or contractual agreements. They should be easy to follow to allow contractors to comply with the applicable regulatory requirements (Refer to the Contractual agreements section). Copies of procedures belonging to a third party and contractual agreements should be made available during inspections/audits.
Documentation should show that the procedures have been put into practice.
Deviations
A deviation is a change or departure from the steps and/or instructions outlined in an approved written procedure. These can be planned or unplanned.
In a planned deviation, the departure should be documented, evaluated and approved before the change is implemented.
In an unplanned deviation, the departure is unexpected and could suggest a systematic deficiency which needs to be resolved.
A systematic deficiency is a fundamental inadequacy that exists within the processes or mechanisms of a pharmacovigilance system. It can arise from inadequate planning, design, or oversight of the system. This deficiency impacts the system’s ability to function effectively, consistently, and achieve its intended goal. It is widespread instead of isolated. A widespread incident is one that is part of a series or pattern of similar occurrences.
When there is an unplanned deviation, you should:
- document the deviation in a timely manner
- carry out an investigation
- evaluate if there is a systematic deficiency
- perform a root cause analysis, as necessary, to assess the cause and impact
- identify and carry out an effective corrective and preventative action plan (CAPA), if appropriate
- evaluate, as necessary, if the corrective and preventative actions taken addressed the root cause of the deviation
Good quality control practices should be in place to detect deviations. You may periodically perform:
- data quality checks
- trend analysis of metrics
Periodic review of trends, performance, and processes will inform continual process improvements that are necessary to enable compliance and maintain a state of control.
Change control
Establish a change control system to allow ongoing process optimization and a continuing state of control. The department responsible for the change should document, evaluate the impact, and approve all changes, as well as identify the appropriate effective date. Any significant change that impacts compliance of your pharmacovigilance responsibilities may require re-validation or verification of systems or processes.
Business continuity plan
Overall considerations
You should establish a risk-based business continuity plan, which can be implemented to enable you to continue critical operations during scenarios such as:
- periods of absence from regular business hours
- unexpected situations, such as:
- an information technology breach
- a network or system failure
- a catastrophic accident
- a natural disaster
- a public health emergency
- a sudden influx of litigation cases
- a geopolitical conflict
- transition periods such as merging or migrating of pharmacovigilance databases
Merging or migrating databases
When merging or migrating pharmacovigilance databases, you should consider the following:
- principles on record retention, data integrity, and maintain an audit trail of the migration process
- principles on validation of computerized systems
- Conduct an impact assessment to:
- identify vulnerable areas of the pharmacovigilance system that may require testing, validation or re-validation, as well as assess the change or compatibility of data format
- ensure merged or migrated data are stored properly
- Develop a risk mitigation strategy to ensure that original data is not lost or altered
Audits
Audits (previously known as self-inspection) help you monitor your organization’s compliance, including the compliance of third-party vendors that you delegate responsibilities to. Your contractual agreements should outline your right and responsibility to conduct periodic audits on third-party vendors according to your risk-based strategy.
Scope
The scope of your audit program should cover all departments or third parties that take part in your pharmacovigilance activities, for example, those that:
- receive, handle, document, process, evaluate, and submit adverse drug reactions (ADRs) and unusual failure in efficacy (UFIE) data
- conduct environmental scanning such as literature searches and regulatory authority database searches
- manage signals
- prepare, review, approve and submit notifications, annual summary reports (ASRs), and issue-related summary reports (IRSRs)
- monitor and notify us of foreign actions related to serious risk of injury
- implement terms and conditions or risk management plans
- maintain and retain records
Overall considerations
Your audit program should include:
- a comprehensive written procedure that describes the functions of your audit program and must address all areas of the applicable regulations
- the need for responsible personnel who are familiar with and understand the applicable Canadian requirements and are qualified with adequate training to conduct the audit
- Note: audit of pharmacovigilance activities internal to the MAH should be conducted by personnel independent from the pharmacovigilance department. However, audits on third-party vendors may be conducted by the pharmacovigilance department.
- the frequency of audits based on a documented risk-based strategy
- prioritization of key processes that impact compliance with the regulations
- documentation and investigation of the root cause and impact when there is a deviation
- a review of any audit findings by senior management, with an appropriate implementation timeline for each CAPA
- follow-up to ensure that all CAPA are completed in an appropriate time
Validation of computerized systems
There should be an assessment to determine if adequate validation has been completed on an electronic system used to capture, process, manage or archive pharmacovigilance activities. Adequacy should be assessed based on the criticality of the system and its intended use. Validation confirms that the system is reliable, credible and will perform as expected. You should document how validation, testing, and re-validation is to be conducted.
Validation reports should be produced to document the results of the validation tests you performed. The results should clearly indicate that the system can be used as intended and is performing as specified.
Modifications or additions made to the electronic system, such as software upgrades or data migration, can affect performance. These can, in turn, affect the quality of the validated applications, and thus the integrity of electronic information. The system’s reliability can also be questioned.
For these reasons, you should assess and approve all changes, using your change control system, to hardware or software used in pharmacovigilance activities. This assessment will also help determine if re-validation is needed and the scope of re-validation.
When conducting a risk-assessment regarding the validation of a computerized system, including when there is a change to the system, ask yourself the following questions such as:
- What is the intended use of the system?
- Is the change on a critical component of the system with direct or indirect impact on regulatory obligations? For example:
- automation rules that impact ADR assessments or ADR submissions
- workflow status of a case that would affect the scheduling for electronic reporting
- quality of data that may affect the assessment on the benefit-risk profile of the drug
Personnel and training
Overall considerations
Employees, in-house or contracted, involved in pharmacovigilance activities are to be qualified and trained on the Canadian requirements that are relevant to their specific responsibilities. This applies to employees such as those who:
- conduct pharmacovigilance activities
- may receive ADR/UFIE, such as:
- sales or as customer service representatives
- receptionists
- medical science liaison staff
- medical information officers
- handle label update such as the regulatory affairs department
Qualified alternate(s) should be identified to carry out duties when responsible personnel is/are absent.
You should ensure that employees:
- receive the level of training that aligns with their title and responsibilities
- receive continuous training relevant to their title and responsibilities
- have the practical experiences that align with their title and responsibilities
You should maintain records for in-house and contracted personnel such as:
- organizational charts
- proof of qualifications
- written work description with specific pharmacovigilance duties
- training records
- name of the designated person who oversee pharmacovigilance activities
- name(s) of qualified healthcare professional
Designated person to oversee pharmacovigilance activities
In addition to the above overall considerations, you should identify a person designated to lead and oversee all pharmacovigilance activities to ensure that all requirements are met. You should also designate an alternative person with the required experience to act in the absence of this designated person. This designated person can either be the same individual or a different individual than the qualified healthcare professional.
Qualified healthcare professional
The qualified healthcare professional (QHCP) is a medically-qualified person such as a physician, dentist, pharmacist, nurse, coroner, or an individual with appropriate healthcare education and therapeutic expertise.
The QHCP should be involved in or oversee key pharmacovigilance activities such as:
- evaluating whether the new information obtained from follow-up efforts is considered clinically or medically significant/relevant that requires expedited reporting
- verifying coding selection of complex/less intuitive ADRs
- providing medical knowledge on evaluations or changes to evaluations related to the seriousness, expectedness, and causality of ADRs, as well as assessments on UFIE
- writing, reviewing, and/or approving annual summary reports (ASRs) and issue-related summary reports (IRSRs)
- providing clinical or medical judgments on signal management activities, as well as any follow-up actions or risk mitigation strategies
- determining if the foreign action is related to a serious risk of injury to human health and relevant to the safety of the drug in Canada
There may be delegation of certain operational activities. The risk-based strategy and process on delegation of these key activities should be justified and documented to enable meaningful collection and assessment of safety information and compliance.
Contractual agreements
Delegation of pharmacovigilance activities
You may delegate a pharmacovigilance activity to a third party. However, if you do, you continue to be ultimately responsible for meeting all regulatory requirements and principles of GVP described in this guidance document. You must ensure processes are in place to control outsourced activities.
You should have a written agreement that is signed and dated between your organization and the third party.
At minimum, a contractual agreement should exist between the MAH and the following parties:
- global entities under the same ownership or corporate structure
- unless processes are already outlined in corporate procedures
- service providers outsourced to conduct the following pharmacovigilance activities on your behalf such as:
- perform literature searches
- execute terms and conditions
- post-marketing studies
- carry out risk minimization measures
- external parties who will receive ADRs or safety data on your behalf
- companies whose names or contact information is/are included in the physical or electronic product label or electronic platforms such as the Canadian importer or third-party private labelers
- MAHs of cross-licensed product
Elements of a contractual agreement on pharmacovigilance activities
Your contractual agreement or its annex, where applicable, should include the following, at minimum:
- roles and responsibilities of each party for each specific delegated activity
- effective date of the agreement
- a list of products that are in scope
- definition of all relevant pharmacovigilance terms
- timeline and scope of safety information to be exchanged
- require written authorization from you if a third-party subcontracts work to another party
- your right and responsibility to audit third-party vendors according to your risk-based strategy
- the third party to assist in audits conducted by you and inspections conducted by regulatory authorities
- need for the third party to provide all records and respond to questions related to the outsourced activities in a timely manner when requested
- need for record retention on activities conducted by the third-party in accordance with regulatory requirements
- dated signature or equivalent legally binding approval of the relevant officials from both parties
- contact information of both parties
Your contractual agreement or its annex should also consider the following, where relevant, according to the risk of impact on your pharmacovigilance system:
- a reconciliation process for pharmacovigilance data, as applicable, outlining the methodology and frequency, to ensure that any missed communication about ADR reports or signals are addressed in a timely manner
- a change control system governing changes to the pharmacovigilance system(s)
- requirements for you to provide the third party with information needed to carry out the contracted operations
- metrics when both parties need to be notified on changes or deviations to the pharmacovigilance system
- communication of any potential impacts on pharmacovigilance activities between you and the third party
The agreement should be reviewed periodically to reflect current requirements and practices.
Cross-licensed product
Each party (licensor and licensee) is responsible for pharmacovigilance activities on its own DIN(s). When your drug is a cross-licensed product, your contractual agreement should ensure that proper communication takes place to enable you and your cross-licensed partner (between the licensor and licensee) to individually fulfill your responsibilities. For example:
- the licensor and licensee should take proactive efforts to update the product label or monograph as necessary
- the licensor should take proactive efforts to communicate with the licensee about any safety signals and considerations on actions for safety reasons
- the licensee should take proactive efforts to communicate with the licensor about any safety signals and considerations on actions for safety reasons
Merger and acquisition
Compliance with requirements set out in the regulations and the GVP principles in this guidance document must continue during transition periods such as a merger, acquisition, or migration of pharmacovigilance databases. A contractual agreement should be in place to outline roles and responsibilities to ensure compliance. You must minimize any impact on ongoing pharmacovigilance activities.
Please refer to the Business continuity plan, Validation of computerized systems, and Maintenance of records sections for further information regarding expectations during transition periods.