Back to Resources

Blog

PSMF Setup and Maintenance Checklist: 14 Controls Built for Day 100

Inspection ReadinessSeptember 2026

Use this 14-point PSMF setup and maintenance checklist to establish a new EU pharmacovigilance system and keep it controlled after go-live.

PSMF Setup and Maintenance Checklist: 14 Controls Built for Day 100

A Newly Created PSMF Is the Easiest Version Your Team Will Ever Manage

The QPPV information is current. Vendor responsibilities have just been agreed. Systems are newly mapped. Product information has been checked. The PSMF reflects the pharmacovigilance system because the system has barely had time to change.

Then go-live happens.

A product is added. An SOP changes. A vendor subcontracts an activity. A database is upgraded. Responsibilities move.

The real test is not whether the PSMF is correct on Day 1.

It is whether the controls established during setup can keep it correct on Day 100.

Key Takeaway: Build the first PSMF for the changes that have not happened yet. Seven controls establish the foundation. Seven more help prevent the PSMF from drifting once the pharmacovigilance system starts moving.


Before Go-Live: 7 PSMF Setup Controls I Would Not Sign Off Without

EMA expects applicants at initial marketing authorisation application to have a description of the pharmacovigilance system that will be functioning when the authorisation is granted and the product enters the market. EMA GVP Module II (Rev. 2) remains the principal EU guidance specifically addressing the Pharmacovigilance System Master File.

Sr. No.Setup ControlWhat It Protects Later
1Define PSMF scope and product coverageMakes clear which pharmacovigilance system and products the file describes.
2Establish QPPV arrangements, PSMF location, and accessKeeps responsibility, back-up arrangements, location, and QPPV access clear from the start.
3Build around the real PV systemPrevents a template from describing processes that do not match actual operations.
4Map responsibilities, systems, sources, and third partiesMakes ownership visible across PV processes, databases, affiliates, and outsourced activities.
5Create controlled source informationReduces product, vendor, system, and organisational information being repeated differently across the PSMF.
6Start PSMF version control and Annex I controls immediatelyPreserves early change history instead of forcing teams to rebuild it later.
7Define access, archival, retrieval, and electronic system controlsKeeps PSMF records readable, protected, and ready for retrieval.

EU rules require version control and accurate retrieval of PSMF records. Changes to QPPV details or PSMF location should also be updated immediately through the Article 57 database.

Ready to launch is more than ready to approve


After Go-Live: 7 PSMF Maintenance Controls That Never Stop

A strong setup can still fail if maintenance depends on periodic clean-up.

Sr. No.Maintenance ControlWhat It Prevents
8Keep the PSMF current as the system changesPrevents the file from describing yesterday's operating model.
9Make external source changes visiblePrevents vendor, SOP, database, product, or organisational updates from depending on memory.
10Impact-assess relevant changes before editingPrevents a change being made without understanding its wider PSMF impact.
11Give Annex information clear owners and review triggersPrevents frequently changing records from slowly falling behind. See PSMF Annex Management and Dynamic Annexes.
12Keep version history and Annex I aligned with controlled changesPrevents gaps between what changed and what the historical record can prove.
13Keep major and critical deviations visible until resolvedPrevents relevant unresolved deviations from becoming disconnected from the PSMF.
14Keep global, local, and outsourced arrangements alignedPrevents country files or delegated responsibilities from drifting away from the controlled PV system.

Regulation (EU) 2025/1466, applicable since 12 February 2026, requires major or critical pharmacovigilance-procedure deviations, their impact, and their management to remain documented until resolution. It also strengthened requirements for third-party roles, safety-data exchange where relevant, audit and inspection arrangements, and further subcontracting.

For multi-country systems, Global and Local PSMFs also need controlled alignment. For delegated activities, see Pharmacovigilance Agreements and the PSMF. PSMF Manager supports centralised global/local workflows and source-change management.


Before Calling the System Ready, Run This Test

Give the team five hypothetical changes:

  • A new product is authorised.
  • A vendor responsibility changes.
  • The safety database is upgraded.
  • A major deviation is opened.
  • The QPPV or PSMF location changes.

For each one, ask:

Who detects it? Who assesses the PSMF impact? Where is the action recorded? Who reviews it? What proves closure?

If the answers depend on searching inboxes or asking who normally handles the task, the PSMF may be complete, but the maintenance model is not.

That distinction matters especially during PV inspections. Differences between the PSMF and the live pharmacovigilance system can raise wider questions about how effectively changes, responsibilities, and oversight are being controlled. EU requirements explicitly require the MAH to keep the PSMF up to date.

Day 1 accuracy has to survive Day 100


Build the Maintenance Model Before the System Starts Moving

The real value of a strong PSMF setup is not visible on Day 1. It becomes visible months later, when changes have occurred and the team can still show how each one was identified, assessed, reviewed, and controlled.

PSMF Manager connects source changes, version history, global and local PSMFs, Annex information, review workflows, and controlled PSMF generation, among others, in one environment.

Request a Demo to see how PSMF Manager can support a new PSMF from initial setup through ongoing maintenance.


FAQs

Frequently Asked Questions

What should be in place before a new EU pharmacovigilance system goes live?+
The organisation should define its QPPV arrangements, PSMF scope and location, systems, processes, Annex records, version controls, access, and maintenance responsibilities.
When does a new MAH need its PSMF ready?+
At initial MAA, applicants should have the description of the pharmacovigilance system that will operate when the marketing authorisation is granted and the product is placed on the market.
Where must an EU PSMF be located?+
At the site in the EU where the MAH's main pharmacovigilance activities are performed or where the QPPV operates.
How should outsourced pharmacovigilance activities be controlled?+
Responsibilities should be clearly defined, with relevant safety-data exchange, audit, inspection, and subcontracting arrangements kept aligned with actual operations.
How often should a PSMF be updated?+
There is no single periodic frequency that replaces change-driven maintenance. The MAH must keep the PSMF up to date as the pharmacovigilance system changes.