Pharmacovigilance automation: ICSR and PSUR controls.
Pharmacovigilance teams can use assisted automation for intake, coding suggestions, narrative drafts and report assembly, but the workflow must preserve completeness, timeliness, validation, medical judgment and accountable human approval.
This guide separates regulatory process requirements from possible automation. The current source set is the EMA GVP collection, including Modules VI, VII and IX, together with the applicable ICH and local reporting rules. Confirm the current version and territory before implementation.
The two halves of pharmacovigilance
PV operations split cleanly into:
1. Case management. Intake, processing, coding, and reporting of individual case safety reports (ICSRs) — the per-event flow, governed by ICH E2B(R3) for case format and the GVP modules / FDA 21 CFR Part 314.80 / Part 600.80 for reporting timelines.
2. Aggregate analysis. Periodic Benefit-Risk Evaluation Reports (PBRERs / PSURs under ICH E2C(R2)), Periodic Adverse Drug Experience Reports (PADERs in the US), Risk Management Plans (RMPs), Development Safety Update Reports (DSURs under ICH E2F), Post-Authorisation Safety Studies (PASS).
The same source data can support several outputs. Assign the applicable reporting route, review responsibilities and approval procedure to each output; an ICSR, PSUR and clinical-trial report do not follow one universal sign-off process.
ICSR processing — where assistance can be tested
A representative ICSR cycle:
- Intake (call center, email, portal, literature).
- Triage (complete minimum information vs. follow-up needed; serious vs. non-serious).
- Data entry into safety database (ARGUS, ARISg, LSMV).
- MedDRA coding of reactions and indications.
- Narrative drafting.
- Medical review and causality assessment.
- Review and approval by the roles assigned in the applicable procedure.
- Submission through the relevant medicines-authority reporting channel, with the jurisdiction, reporting clock and acknowledgement recorded.
ICSR reporting deadlines: distinguish postmarketing and clinical-trial rules
Configure the clock from the applicable rule and reporting context. The examples below cover common EU post-authorisation and US routes; they are not a complete global reporting matrix.
| Reporting context | Report and recipient | Initial deadline and controlling source |
|---|---|---|
| EU post-authorisation | Valid serious ICSRs from EU or non-EU sources; valid non-serious EU ICSRs, to EudraVigilance | Serious: 15 days. Non-serious EU: 90 days. The clock starts with receipt of the minimum information. GVP VI.B.7 and VI.C.3. |
| US postmarketing, approved drugs and licensed biologics | Serious and unexpected adverse experiences, to FDA | As soon as possible, within 15 calendar days of initial receipt. Other reports follow the applicable periodic-reporting provisions. 21 CFR 314.80(c) and 600.80(c). |
| US clinical trials under an IND | Unexpected fatal or life-threatening suspected adverse reactions, to FDA | As soon as possible, within 7 calendar days of initial receipt by the sponsor. FDA guidance on 21 CFR 312.32(c)(2). |
| US clinical trials under an IND | Other potential serious risks qualifying under 21 CFR 312.32(c)(1), to FDA and participating investigators | As soon as possible, within 15 calendar days after the sponsor determines that the information qualifies for reporting. FDA guidance on 21 CFR 312.32(c)(1). |
Store the first-receipt date, the date minimum information became available, reportability decisions and later information separately. Test follow-up clocks, delegated intake and local requirements before deployment.
Intake, coding and drafting are useful candidates for a bounded pilot:
Triage automation
Classification can route likely non-cases for review and prioritise material that may meet minimum case criteria. Performance must be measured on representative data and monitored after change.
Incomplete does not mean discard. Under GVP VI.B.2–3, reports missing minimum information should be retained in the pharmacovigilance system and followed up with due diligence. Document attempts to obtain the missing elements; assess submission when the report becomes valid. Valid cases may also need further follow-up.
Validation example: submit a test report with a suspected drug and reaction but missing patient information. Confirm that the workflow retains the report, creates a follow-up task and preserves both the initial receipt and completion dates when the missing information arrives.
MedDRA coding
MedDRA (Medical Dictionary for Regulatory Activities) coding of reaction terms is rules-based at heart but linguistically tricky. Free-text reaction descriptions ("a pounding feeling in the chest after eating") need mapping to a Lowest Level Term (LLT), which rolls up through Preferred Term (PT), High Level Term (HLT), High Level Group Term (HLGT), and System Organ Class (SOC).
AI can suggest LLTs and PTs, but match rate varies by language, product, source channel and case complexity. Validate against expert-coded ground truth, review disagreements, monitor dictionary-version changes and retain the final human decision.
Narrative drafting
Case narratives describe the patient, the suspect drug, the reaction, the temporal relationship, treatment, dechallenge, rechallenge, and outcome. Industry-standard narrative templates exist; LLMs are good at populating them from the structured case data.
The qualified-person review still happens. The reviewer checks completeness, chronology, clinical inference, consistency with structured fields and the final signed record.
Duplicate detection
Cases reported through multiple channels can describe the same event differently. Semantic similarity can add candidates to established matching rules; a validated decision process is still needed before records are merged or linked.
Aggregate reports — PSUR / PBRER drafting
The Periodic Safety Update Report (now formally Periodic Benefit-Risk Evaluation Report, PBRER, under ICH E2C(R2)) covers a defined data lock point period and includes:
- Worldwide marketing approval status.
- Actions taken in the reporting interval for safety reasons.
- Changes to reference safety information.
- Estimated exposure and use patterns.
- Data in summary tabulations (signals, ICSRs by SOC, etc.).
- Summaries of significant findings from clinical trials, non-clinical data, literature, and other sources.
- Signal and risk evaluation.
- Benefit evaluation, integrated benefit-risk analysis.
- Conclusions and actions.
The data tabulations come from controlled safety data; the prose comes from the medical writer or safety physician. Assisted drafting should link every statement and table to its data lock point, source extract, calculation or approved analysis.
A scoped Sia RegAI workflow can structure source extracts and prepare section drafts for review. The medical writer checks the narrative; the safety function owns signal and benefit-risk analysis; the accountable qualified person approves the final report.
Signal management
GVP Module IX (signal management) defines the lifecycle: signal detection → validation → confirmation → analysis and prioritisation → assessment → recommendation for action. Disproportionality methods (PRR, ROR, IC, EBGM) over EudraVigilance / FAERS / company database produce candidate signals; humans validate.
Where AI helps:
- Signal detection support. Run approved methods on the authorised data set and route candidates into the governed signal process.
- Literature surveillance. Continuous monitoring of MEDLINE, EMBASE, Cochrane, and conference abstracts for adverse-event signals related to in-scope products. Returns relevant articles with abstract summaries; the safety physician decides whether to investigate.
- Pre-validation triage. Pre-classifying candidate signals by likelihood of true signal vs. expected reaction, helping signal-management teams prioritise.
Critical: the regulator-facing decision (is this a confirmed signal? what action?) stays with the safety physician. AI is upstream filtering and pattern detection.
What stays human (and why)
The line we draw with PV clients:
- Causality assessment. The medical judgment of whether a drug caused an adverse event is signed by a qualified person. AI doesn't sign causality.
- Final medical review of cases. Every serious case gets reviewed by a safety physician before submission. AI accelerates the review (drafting, tabulation) but doesn't replace it.
- QPPV sign-off on aggregate reports. The benefit-risk conclusion is the QPPV's. AI drafts; QPPV decides.
- Reporting decisions on borderline cases. Whether to expedite a borderline-serious case is a regulatory and medical judgment. AI supports; humans decide.
Get those four right and the rest can be aggressive about automation.
Where Sia RegAI helps
For a scoped PV implementation, define the authoritative EMA GVP, ICH, FDA and local source set before configuring any workflow. RegReview can monitor those sources, preserve versions and route changes to the relevant safety reviewers. RegMatcher can connect approved obligations to SOPs, controls, owners and evidence, so the assessment can be refreshed without losing the earlier interpretation.
Within that governed source and review model, potential workflow uses include:
- Triage and route inbound case streams against the modular GVP definitions.
- Draft case narratives and MedDRA coding for human review.
- Generate PBRER / PSUR / PADER / DSUR sections from underlying data.
- Surface gap analysis between SOPs and current GVP module text — useful when GVP modules update or for regulator inspection prep.
- Cross-map regulatory obligations to your QMS and SOP library.
Require source links, input versions, prompts or rules, reviewer edits, approvals and export logs as acceptance criteria; verify them during validation and inspection rehearsal.
See the PV compliance workflow
Choose one reporting obligation and one SOP for the discussion. See how source changes, control gaps, accountable reviewers and validation evidence can be connected in RegReview and RegMatcher.
Validation and evidence checklist
| Use case | Failure to test | Evidence to retain |
|---|---|---|
| Case intake | Missed minimum case or incorrect seriousness route | Representative test set, sensitivity, false-negative review, exception log |
| Incomplete report | Discarded record, missed follow-up or overwritten receipt date | Retained input, missing-element task, dated follow-up and reporting-clock test |
| Reporting route | Clinical-trial clock applied to postmarketing case, or wrong recipient | Jurisdiction and product-status matrix, rule citation, due-date tests and acknowledgement |
| MedDRA suggestion | Wrong term, level or dictionary version | Gold-standard comparison, disagreement review, version and reviewer |
| Narrative draft | Omission, unsupported inference or field inconsistency | Source-to-sentence links, edit history, medical approval |
| Duplicate candidate | Incorrect merge or failure to link | Threshold study, candidate pairs, human disposition |
| Aggregate report | Wrong data lock point, denominator or unsupported conclusion | Controlled extract, calculation lineage, review and sign-off |
How 21 CFR Part 11 and EMA GVP affect an AI-assisted workflow
AI does not remove the need to determine which electronic records are governed by applicable predicate rules and 21 CFR Part 11. FDA's scope-and-application guidance explains that Part 11 applies when regulated records are maintained or submitted electronically under FDA requirements. Begin validation with record classification and intended use—not a generic assertion that a tool is “Part 11 compliant.”
EMA GVP likewise requires a functioning pharmacovigilance quality system. For AI-assisted case processing, signal support or aggregate-report drafting, cover approved procedures, responsibilities, training, documentation, audit, compliance monitoring, business continuity and management review. GVP Module I details the quality-system expectations.
| Control question | Evidence |
|---|---|
| What regulated decision or record does the workflow support? | Intended-use statement and record inventory |
| Which source data and model or rule version produced the output? | Versioned input, configuration and execution log |
| Can a reviewer trace a generated statement to its source? | Source links, field-level lineage and review history |
| Which errors must the validation set detect? | Risk-based test cases, acceptance criteria and exception analysis |
| Who can approve, change or release the workflow? | Role matrix, access record and change approval |
| How are overrides and reviewer edits retained? | Audit trail and signed review record |
| What happens if the service or integration fails? | Business-continuity procedure and tested fallback |
| How is performance monitored after release? | Quality indicators, drift review, deviations and CAPA records |
Frequently asked questions
Does FDA certify software as 21 CFR Part 11 compliant?
Do not frame compliance as an FDA product certification. The regulated organisation must determine scope, intended use, applicable predicate rules and whether its controls and records satisfy the relevant requirements.
Can AI make the final pharmacovigilance causality decision?
AI may support data preparation or drafting, but medical and regulatory judgements should remain with qualified, authorised reviewers under approved procedures.
What is the minimum evidence for validating AI-assisted case processing?
Retain intended use, risk assessment, representative test data, acceptance criteria, results, deviations, approvals, versions, source-to-output traceability, reviewer history and ongoing performance monitoring.
Common pitfalls
- Treating AI ICSR triage as definitive. Err on inclusion. The cost of a missed case is regulatory; the cost of a false-positive is a few minutes of case-manager time.
- Letting AI draft causality. Causality is a medical judgment. AI can describe the case; it shouldn't classify causality without a qualified person co-signing.
- Generating signals without validating. Disproportionality methods produce many false positives. Always validate before reporting.
- Over-trusting MedDRA coding accuracy. Aggregate accuracy can hide material errors. Review disagreements by seriousness, expectedness, product, language and source channel.
- Using one reporting clock everywhere. Separate postmarketing and clinical-trial routes, jurisdictions, initial reports and follow-ups. Verify each trigger and deadline against the applicable source; keep aggregate-report schedules distinct.
Closing
The sound business case is not a generic automation percentage. Establish a baseline for volume, quality, rework, timeliness and reviewer effort; pilot one bounded use case; compare like for like; and expand only when safety and compliance acceptance criteria remain satisfied.