Back to Sia website
Sia RegAI  /  Blog  /  Pharmacovigilance automation
Practical guide · Pharma & Life Sciences

Pharmacovigilance automation: ICSR and PSUR controls.

Published April 30, 2026 Updated September 6, 2026 10-minute read By Cyril Sayada

Pharmacovigilance teams can use assisted automation for intake, coding suggestions, narrative drafts and report assembly, but the workflow must preserve completeness, timeliness, validation, medical judgment and accountable human approval.

Direct answer: automate preparation, not accountability. Use AI outputs as controlled suggestions; validate the system for its intended use, measure false negatives and coding disagreement, preserve every source and edit, and require qualified review for medical and regulatory decisions.

This guide separates regulatory process requirements from possible automation. The current source set is the EMA GVP collection, including Modules VI, VII and IX, together with the applicable ICH and local reporting rules. Confirm the current version and territory before implementation.

The two halves of pharmacovigilance

PV operations split cleanly into:

1. Case management. Intake, processing, coding, and reporting of individual case safety reports (ICSRs) — the per-event flow, governed by ICH E2B(R3) for case format and the GVP modules / FDA 21 CFR Part 314.80 / Part 600.80 for reporting timelines.

2. Aggregate analysis. Periodic Benefit-Risk Evaluation Reports (PBRERs / PSURs under ICH E2C(R2)), Periodic Adverse Drug Experience Reports (PADERs in the US), Risk Management Plans (RMPs), Development Safety Update Reports (DSURs under ICH E2F), Post-Authorisation Safety Studies (PASS).

The same source data can support several outputs. Assign the applicable reporting route, review responsibilities and approval procedure to each output; an ICSR, PSUR and clinical-trial report do not follow one universal sign-off process.

ICSR processing — where assistance can be tested

A representative ICSR cycle:

  1. Intake (call center, email, portal, literature).
  2. Triage (complete minimum information vs. follow-up needed; serious vs. non-serious).
  3. Data entry into safety database (ARGUS, ARISg, LSMV).
  4. MedDRA coding of reactions and indications.
  5. Narrative drafting.
  6. Medical review and causality assessment.
  7. Review and approval by the roles assigned in the applicable procedure.
  8. Submission through the relevant medicines-authority reporting channel, with the jurisdiction, reporting clock and acknowledgement recorded.

ICSR reporting deadlines: distinguish postmarketing and clinical-trial rules

Configure the clock from the applicable rule and reporting context. The examples below cover common EU post-authorisation and US routes; they are not a complete global reporting matrix.

Reporting contextReport and recipientInitial deadline and controlling source
EU post-authorisationValid serious ICSRs from EU or non-EU sources; valid non-serious EU ICSRs, to EudraVigilanceSerious: 15 days. Non-serious EU: 90 days. The clock starts with receipt of the minimum information. GVP VI.B.7 and VI.C.3.
US postmarketing, approved drugs and licensed biologicsSerious and unexpected adverse experiences, to FDAAs soon as possible, within 15 calendar days of initial receipt. Other reports follow the applicable periodic-reporting provisions. 21 CFR 314.80(c) and 600.80(c).
US clinical trials under an INDUnexpected fatal or life-threatening suspected adverse reactions, to FDAAs soon as possible, within 7 calendar days of initial receipt by the sponsor. FDA guidance on 21 CFR 312.32(c)(2).
US clinical trials under an INDOther potential serious risks qualifying under 21 CFR 312.32(c)(1), to FDA and participating investigatorsAs soon as possible, within 15 calendar days after the sponsor determines that the information qualifies for reporting. FDA guidance on 21 CFR 312.32(c)(1).

Store the first-receipt date, the date minimum information became available, reportability decisions and later information separately. Test follow-up clocks, delegated intake and local requirements before deployment.

Intake, coding and drafting are useful candidates for a bounded pilot:

Triage automation

Classification can route likely non-cases for review and prioritise material that may meet minimum case criteria. Performance must be measured on representative data and monitored after change.

Incomplete does not mean discard. Under GVP VI.B.2–3, reports missing minimum information should be retained in the pharmacovigilance system and followed up with due diligence. Document attempts to obtain the missing elements; assess submission when the report becomes valid. Valid cases may also need further follow-up.

Validation example: submit a test report with a suspected drug and reaction but missing patient information. Confirm that the workflow retains the report, creates a follow-up task and preserves both the initial receipt and completion dates when the missing information arrives.

MedDRA coding

MedDRA (Medical Dictionary for Regulatory Activities) coding of reaction terms is rules-based at heart but linguistically tricky. Free-text reaction descriptions ("a pounding feeling in the chest after eating") need mapping to a Lowest Level Term (LLT), which rolls up through Preferred Term (PT), High Level Term (HLT), High Level Group Term (HLGT), and System Organ Class (SOC).

AI can suggest LLTs and PTs, but match rate varies by language, product, source channel and case complexity. Validate against expert-coded ground truth, review disagreements, monitor dictionary-version changes and retain the final human decision.

Narrative drafting

Case narratives describe the patient, the suspect drug, the reaction, the temporal relationship, treatment, dechallenge, rechallenge, and outcome. Industry-standard narrative templates exist; LLMs are good at populating them from the structured case data.

The qualified-person review still happens. The reviewer checks completeness, chronology, clinical inference, consistency with structured fields and the final signed record.

Duplicate detection

Cases reported through multiple channels can describe the same event differently. Semantic similarity can add candidates to established matching rules; a validated decision process is still needed before records are merged or linked.

Aggregate reports — PSUR / PBRER drafting

The Periodic Safety Update Report (now formally Periodic Benefit-Risk Evaluation Report, PBRER, under ICH E2C(R2)) covers a defined data lock point period and includes:

  • Worldwide marketing approval status.
  • Actions taken in the reporting interval for safety reasons.
  • Changes to reference safety information.
  • Estimated exposure and use patterns.
  • Data in summary tabulations (signals, ICSRs by SOC, etc.).
  • Summaries of significant findings from clinical trials, non-clinical data, literature, and other sources.
  • Signal and risk evaluation.
  • Benefit evaluation, integrated benefit-risk analysis.
  • Conclusions and actions.

The data tabulations come from controlled safety data; the prose comes from the medical writer or safety physician. Assisted drafting should link every statement and table to its data lock point, source extract, calculation or approved analysis.

A scoped Sia RegAI workflow can structure source extracts and prepare section drafts for review. The medical writer checks the narrative; the safety function owns signal and benefit-risk analysis; the accountable qualified person approves the final report.

Signal management

GVP Module IX (signal management) defines the lifecycle: signal detection → validation → confirmation → analysis and prioritisation → assessment → recommendation for action. Disproportionality methods (PRR, ROR, IC, EBGM) over EudraVigilance / FAERS / company database produce candidate signals; humans validate.

Where AI helps:

  • Signal detection support. Run approved methods on the authorised data set and route candidates into the governed signal process.
  • Literature surveillance. Continuous monitoring of MEDLINE, EMBASE, Cochrane, and conference abstracts for adverse-event signals related to in-scope products. Returns relevant articles with abstract summaries; the safety physician decides whether to investigate.
  • Pre-validation triage. Pre-classifying candidate signals by likelihood of true signal vs. expected reaction, helping signal-management teams prioritise.

Critical: the regulator-facing decision (is this a confirmed signal? what action?) stays with the safety physician. AI is upstream filtering and pattern detection.

What stays human (and why)

The line we draw with PV clients:

  • Causality assessment. The medical judgment of whether a drug caused an adverse event is signed by a qualified person. AI doesn't sign causality.
  • Final medical review of cases. Every serious case gets reviewed by a safety physician before submission. AI accelerates the review (drafting, tabulation) but doesn't replace it.
  • QPPV sign-off on aggregate reports. The benefit-risk conclusion is the QPPV's. AI drafts; QPPV decides.
  • Reporting decisions on borderline cases. Whether to expedite a borderline-serious case is a regulatory and medical judgment. AI supports; humans decide.

Get those four right and the rest can be aggressive about automation.

Where Sia RegAI helps

For a scoped PV implementation, define the authoritative EMA GVP, ICH, FDA and local source set before configuring any workflow. RegReview can monitor those sources, preserve versions and route changes to the relevant safety reviewers. RegMatcher can connect approved obligations to SOPs, controls, owners and evidence, so the assessment can be refreshed without losing the earlier interpretation.

Within that governed source and review model, potential workflow uses include:

  • Triage and route inbound case streams against the modular GVP definitions.
  • Draft case narratives and MedDRA coding for human review.
  • Generate PBRER / PSUR / PADER / DSUR sections from underlying data.
  • Surface gap analysis between SOPs and current GVP module text — useful when GVP modules update or for regulator inspection prep.
  • Cross-map regulatory obligations to your QMS and SOP library.

Require source links, input versions, prompts or rules, reviewer edits, approvals and export logs as acceptance criteria; verify them during validation and inspection rehearsal.

See the PV compliance workflow

Choose one reporting obligation and one SOP for the discussion. See how source changes, control gaps, accountable reviewers and validation evidence can be connected in RegReview and RegMatcher.

Validation and evidence checklist

Use caseFailure to testEvidence to retain
Case intakeMissed minimum case or incorrect seriousness routeRepresentative test set, sensitivity, false-negative review, exception log
Incomplete reportDiscarded record, missed follow-up or overwritten receipt dateRetained input, missing-element task, dated follow-up and reporting-clock test
Reporting routeClinical-trial clock applied to postmarketing case, or wrong recipientJurisdiction and product-status matrix, rule citation, due-date tests and acknowledgement
MedDRA suggestionWrong term, level or dictionary versionGold-standard comparison, disagreement review, version and reviewer
Narrative draftOmission, unsupported inference or field inconsistencySource-to-sentence links, edit history, medical approval
Duplicate candidateIncorrect merge or failure to linkThreshold study, candidate pairs, human disposition
Aggregate reportWrong data lock point, denominator or unsupported conclusionControlled extract, calculation lineage, review and sign-off

How 21 CFR Part 11 and EMA GVP affect an AI-assisted workflow

AI does not remove the need to determine which electronic records are governed by applicable predicate rules and 21 CFR Part 11. FDA's scope-and-application guidance explains that Part 11 applies when regulated records are maintained or submitted electronically under FDA requirements. Begin validation with record classification and intended use—not a generic assertion that a tool is “Part 11 compliant.”

EMA GVP likewise requires a functioning pharmacovigilance quality system. For AI-assisted case processing, signal support or aggregate-report drafting, cover approved procedures, responsibilities, training, documentation, audit, compliance monitoring, business continuity and management review. GVP Module I details the quality-system expectations.

Control questionEvidence
What regulated decision or record does the workflow support?Intended-use statement and record inventory
Which source data and model or rule version produced the output?Versioned input, configuration and execution log
Can a reviewer trace a generated statement to its source?Source links, field-level lineage and review history
Which errors must the validation set detect?Risk-based test cases, acceptance criteria and exception analysis
Who can approve, change or release the workflow?Role matrix, access record and change approval
How are overrides and reviewer edits retained?Audit trail and signed review record
What happens if the service or integration fails?Business-continuity procedure and tested fallback
How is performance monitored after release?Quality indicators, drift review, deviations and CAPA records
Direct answer: Validate an AI-assisted pharmacovigilance workflow against its intended use and regulatory risk. Preserve source data, configuration, versions, reviewer decisions, audit trails and test evidence; monitor errors after release; and keep qualified humans accountable for medical and regulatory judgement.

Frequently asked questions

Does FDA certify software as 21 CFR Part 11 compliant?

Do not frame compliance as an FDA product certification. The regulated organisation must determine scope, intended use, applicable predicate rules and whether its controls and records satisfy the relevant requirements.

Can AI make the final pharmacovigilance causality decision?

AI may support data preparation or drafting, but medical and regulatory judgements should remain with qualified, authorised reviewers under approved procedures.

What is the minimum evidence for validating AI-assisted case processing?

Retain intended use, risk assessment, representative test data, acceptance criteria, results, deviations, approvals, versions, source-to-output traceability, reviewer history and ongoing performance monitoring.

Common pitfalls

  • Treating AI ICSR triage as definitive. Err on inclusion. The cost of a missed case is regulatory; the cost of a false-positive is a few minutes of case-manager time.
  • Letting AI draft causality. Causality is a medical judgment. AI can describe the case; it shouldn't classify causality without a qualified person co-signing.
  • Generating signals without validating. Disproportionality methods produce many false positives. Always validate before reporting.
  • Over-trusting MedDRA coding accuracy. Aggregate accuracy can hide material errors. Review disagreements by seriousness, expectedness, product, language and source channel.
  • Using one reporting clock everywhere. Separate postmarketing and clinical-trial routes, jurisdictions, initial reports and follow-ups. Verify each trigger and deadline against the applicable source; keep aggregate-report schedules distinct.

Closing

The sound business case is not a generic automation percentage. Establish a baseline for volume, quality, rework, timeliness and reviewer effort; pilot one bounded use case; compare like for like; and expand only when safety and compliance acceptance criteria remain satisfied.

Primary sources

Connect your PV obligations to SOPs and evidence.

Explore a scoped workflow for regulatory monitoring and SOP gap assessment, with the source, owner, reviewer and evidence visible together.