Back to Resources

Blog

Connected PV Systems and PSMF Readiness

Data IntegrationJuly 2026

Learn how connected safety, quality, regulatory, and vendor data supports controlled PSMF updates and continuous inspection readiness.

Connected PV Systems and PSMF Readiness

How Connected PV Data Keeps the PSMF Inspection-Ready

An inspection request arrives, and the PSMF appears complete.

Then the inconsistencies begin to surface.

The QPPV information reflects a previous office location. A vendor listed in the PSMF is operating under a revised agreement. A business continuity test has been completed, but its evidence remains in an email inbox. A newly authorised product appears in the regulatory system but not in Annex H.

None of this information is missing.

It exists in different systems, owned by different teams, moving at different speeds. The PSMF becomes outdated because the changes occurring around it do not enter a controlled review process quickly enough.

That is the real purpose of connected PV systems. They do not turn the PSMF into an automatically rewritten document. They help relevant operational changes reach the right reviewer before they become potential inspection gaps.

Key Takeaways: An inspection-ready PSMF depends on timely information from various safety, quality, regulatory, and vendor systems. Each source should have a defined owner, a review trigger, and a controlled route for impact assessment and approval. Connected data should support human judgment and QPPV oversight, not bypass them.


The PSMF Is Where Systems Meet

The PSMF must describe the pharmacovigilance system as it operates at the current time. It should support QPPV oversight, audits, inspections, and the identification of deficiencies or non-compliance.

But the information needed to maintain that description rarely sits in one application.

Data SourceTypical ChangePotential PSMF ImpactEvidence That Should Remain Available
Safety systemsIntake changes, database migration, validation updates, reconciliation changesSources of safety data, computerised systems, PV processesData-flow records, validation documentation, procedures, reconciliation evidence
Quality systemsAudit finding, deviation, CAPA, training or procedure updateQuality-system description, audit information, procedures, Annex IAudit reports, CAPA status, effectiveness checks, approved procedures
Regulatory systemsNew product, territory, indication, withdrawal, marketing-status changeSystem scope, QPPV workload, product list in Annex HApproved product and territory records
Vendor systemsNew agreement, service transfer, subcontractor, audit or escalation changeOrganisational structure, delegated activities, agreements, oversight recordsCurrent agreements, audit evidence, KPIs, escalation and CAPA records

EMA GVP Module II acknowledges that frequently updated annex information may come from controlled systems such as electronic document-management platforms and regulatory databases. The history of superseded information must still remain controlled and available.


Four operating systems. One controlled PSMF.

Follow One Change Across the Connected System

Consider a vendor transition involving ICSR intake and case processing.

The contract-management system records the new service provider and effective date. That information alone is not enough to keep the PSMF current.

The transition may affect several areas at once.

Safety data: The source of incoming cases, reconciliation process, data-transfer route, and responsible system may change.

Quality data: The transition may introduce qualification activities, training requirements, audit actions, deviations, or CAPAs.

Regulatory data: The vendor's scope may differ by product, country, or reporting responsibility.

Vendor data: Agreements, contacts, escalation routes, service levels, and oversight measures need to reflect the new arrangement.

PSMF content: The organisational structure, contractual description, safety-data sources, procedures, systems, annex information, and change history may all require assessment.

EMA GVP Module II identifies changes to safety databases, significant PV services, contractual arrangements, and organisational structures as changes that may require PSMF control and QPPV notification. It also requires robust processes to continuously identify relevant changes.

A connected process does not simply copy the new agreement into a PSMF Annex. It asks where the change affects the pharmacovigilance system and whether the approved PSMF still describes that system accurately.


Connected Does Not Mean Automatically Approved

Connectivity can reduce information lag, but uncontrolled automation can create a different compliance problem.

Not every source-system update belongs in the approved PSMF.

A contract may be uploaded before its effective date. A CAPA may be administratively closed while its effectiveness check remains pending. A regulatory record may be incomplete. A system update may have no material effect on the PSMF.

The controlled sequence should be:

Source Change → Notification → Impact Assessment → Content Review → Approval → Controlled Version

This sequence preserves accountability.

The reviewer can determine whether the change affects the PSMF, which sections or annexes require revision, and what evidence supports the decision. The QPPV retains access and oversight, while the approved file remains protected from unreviewed inputs.

EMA GVP Module II requires documented changes to include the date, the responsible person, and the nature of the change. It also requires the QPPV to have permanent access to current information, including information held in systems used to generate annex content.


Connected data should accelerate review, not bypass control.

Inspection Readiness Is a Retrieval Test

A polished PDF does not prove that the supporting system is controlled.

A stronger test is whether the organisation can retrieve connected evidence without starting a cross-functional search after the inspection request arrives.

Select one recent system change and ask:

  • Where was the change first recorded?
  • Who determined whether it affected the PSMF?
  • Which sections and annexes were assessed?
  • What evidence supported the decision?
  • Who reviewed and approved the update?
  • Which PSMF version first reflected the change?
  • Can the previous approved version still be retrieved?

This test is more revealing than checking whether the latest document opens correctly.

It shows whether information can move from the operating system into the PSMF without losing ownership, rationale, approval, or historical context.

Competent authorities may request the PSMF within seven days, and immediate access may also be required at the stated PSMF location or QPPV site. The PSMF seven-day requirement becomes difficult when evidence must be reconstructed from multiple teams and repositories.


How PSMF Manager Supports Connected PV Workflows

PSMF Manager can support connections with compatible external systems and document repositories through available integration options, including webhooks or APIs. When a linked source changes, the platform can notify users and create a corresponding change request for review. Human review and approval remain part of the controlled workflow.

The External Data Sources integration helps bring operational changes into the PSMF process instead of leaving them unnoticed in separate repositories.

The Tracked Changes workflow highlights edits, records user attribution, and preserves review comments and approval activity.

The Version History feature preserves approved historical states, timestamps, user activity, and change descriptions, allowing teams to retrieve the PSMF that was active at a specific point in time.

Once the content is reviewed and approved, the PSMF Generation workflow compiles the latest approved information into a read-only PDF with sections, annexes, bookmarks, and Annex I change-log information.

Technology does not replace the MAH's responsibility or the QPPV's oversight. It provides a controlled path for relevant changes to reach the PSMF sooner and with a defensible history.


The PSMF Should Not Be the Last System to Know

A PSMF becomes outdated when operational changes remain trapped inside the systems where they began.

Safety teams may know that an intake route changed. Quality may know that a CAPA altered a process. Regulatory Affairs may know that the product portfolio expanded. Vendor Management may know that an agreement was revised.

Inspection readiness depends on whether those changes enter one coordinated governance process.

A connected PV model reduces the delay between an operational change and its controlled reflection in the PSMF. It gives the QPPV clearer visibility and preserves the evidence needed to demonstrate how each approved update was assessed.

Request a demonstration of PSMF Manager to see how external data connections, structured reviews, version history, and controlled PSMF generation can support continuous inspection readiness.


FAQs

Frequently Asked Questions

Does a connected PV system require every platform to be integrated?+
No. The objective is not to connect every application. Organisations should prioritise sources that contain information capable of materially changing the pharmacovigilance system or PSMF content.
Who should own the decision to update the PSMF?+
Source-data owners should communicate relevant changes, but the PSMF impact decision should follow the organisation's defined governance process. This may involve the PSMF coordinator, process owner, quality function, and QPPV, depending on the change.
Should every detected source change appear in Annex I?+
Not necessarily. Every relevant change should be assessed, but only approved changes affecting the controlled PSMF should be reflected according to the organisation's change-control and Annex I process. The rationale for a decision not to update should be retained where appropriate.
How can an organisation test whether its connected PSMF process works?+
Select a recent change from a source system and trace it through notification, impact assessment, review, approval, and the resulting PSMF version. The organisation should be able to retrieve each stage without reconstructing the history manually.