Gyöngyi Mezey
Director of Product Management, Qinecsa Solutions
Abstract: Safety databases transformed individual case processing more than two decades ago, yet the surrounding workflows have changed little since. Core pharmacovigilance activities such as aggregate report scheduling, PSMF governance, PV agreement and term collection management, and affiliate oversight remain heavily manual – to the point that up to half of expert PV time at large pharma companies is still consumed by administrative coordination rather than active safety assessment. At the same time, compliance risks are accumulating across fragmented systems. Gyöngyi Mezey, Director of Product Management at Qinecsa Solutions, discusses why this situation persists, where risk is most concentrated and what a pragmatic path to automation looks like.
For large pharma, a staggering 40-50 per cent of expert pharmacovigilance time is currently spent on work that has nothing to do with active, scientific PV. Far too much effort is still being expended on the mechanics of scheduling reports, chasing contributors and managing documents — laborious processes that still rely heavily on cumbersome workarounds.
Although case processing was transformed by safety databases in the early 2000s (Oracle Argus, ArisGlobal LifeSphere, Veeva Vault Safety and their predecessors brought welcome rigour to individual case safety reporting), these platforms were never designed to automate the activity surrounding case management. Because of this, aggregate report scheduling, pharmacovigilance system master file (PSMF) management, PV agreement maintenance, term collection and affiliate oversight have been commonly handled using Excel workbooks, shared drives and email inboxes.
That situation has persisted largely due to internal budget prioritisation challenges and the assumption that “transformation” would constitute a complete platform overhaul. It often takes a difficult inspection to surface the impact of that inertia.
Where the burden is greatest
The workflows beset by the largest inefficiencies are document-heavy, involve multiple contributors, recur on a defined cycle and demand a traceable record that ad-hoc systems don’t support.
For a large pharma company with an extensive marketed portfolio, aggregate reporting alone could mean hundreds of Periodic Safety Update Reports (PSURs), Periodic Adverse Drug Experience Reports (PADERs), Development Safety Update Reports (DSURs) and annual safety reports due across the year. Coordinating those schedules, assigning contributors, managing versions and tracking submissions is a substantial overhead in its own right. When this is managed using spreadsheets and email chains (that grow with every new product added to the portfolio) the burden becomes unsustainable, even assuming that additional team members are available to share the load.
The PSMF creates a parallel set of problems, being both a regulatory requirement and a live document that must accurately reflect the current state of a company’s PV system. For companies managing multiple PSMFs across EU and local variations, there must be structured review cycles, controlled versioning and clear sign-off records. Yet companies without an auditproof review process are typically reliant on a shared drive with no formal oversight. This means there is no reliable way to establish who made a particular change, or whether anyone actually reviewed the document before it went out.
The practical consequences of this can be significant. A PSMF submitted for inspection might inadvertently contain a duplicated chapter, because this wasn’t picked up during a formal review and there is no audit trail to help determine how it happened, or there is inconsistent data within the numerous annexes. All of this becomes increasingly relevant in the light of heightened regulatory expectations around inspection readiness and documentation traceability under EU GVP Module II.
As affiliate and vendor structures grow more complex and partner ecosystems expand (e.g. through licensed products, co-promotion arrangements and growing affiliate networks), the number of PV agreements requiring authoring, review, approval and exchange multiplies. Managing all of this using piecemeal workarounds leads to untracked document versions, poor oversight of agreement status and compliance exposure.
Term collection adds its own complications. Oracle’s Thesaurus Management System — for years the only established option in the market — is now widely regarded as outdated and poorly supported, and the home-built solutions many companies have constructed in its place bring their own validation problems. Teams relying on either of these scenarios generally find that they are fighting to keep up with bi-annual MedDRA updates, while lacking vital data integrity (which signal detection work depends on).
The affiliate blind spot
Large pharmaceutical companies operating through local PV affiliates face a further layer of coordination risk. Local affiliates tend to manage their own ICSR processing, submissions, reconciliation and agreements through locally-maintained tools that sit outside the central system. Central PV functions then have to piece together their oversight from periodic updates, email exchanges and whatever reporting structures have evolved over time.
In many cases, central teams are relying on reconstructed visibility rather than real-time oversight; ultimately holding a less current or complete picture than is assumed. Under routine operating conditions that may be manageable, but what happens when an inspection demands a precise account of both central and local activity simultaneously, or a serious adverse event demands rapid escalation across territories?
The limits of case-centric design
Ultimately, highly-trained employees with deep scientific expertise in drug safety are spending far too high a percentage of their working week on administrative coordination, reliant on systems and workaround that just aren’t up to the task. This translates to unpalatable volumes of skilled hours diverted from actual safety work, and compliance risk that compounds wherever documentation cannot be traced.
Safety databases excel at case management, but modern PV demands more than that. Yet replacing an embedded safety database is not something most large organisations would seriously contemplate. The validation burden, combined with the disruption to live operations, makes this a non-starter in all but the most exceptional circumstances. The practical path forward for most organisations, then, must be to address the surrounding workflows separately, building capabilities that integrate with the existing safety database rather than replacing it.
The audit trail test
One viable way forward is to introduce new capabilities to the existing estate incrementally, beginning with problem areas constituting the biggest time, cost and compliance exposure. If an experienced PV professional is spending up to half of their working time coordinating aggregate reports, that cost is easily calculable. Add in the harder-to-quantify cost of reconstructing records ahead of an inspection and the risk surrounding a PSMF with little-to-no traceability across its review cycle, and the case for action tends to make itself.
Whatever the identified issue, there is a more direct test of whether the current set-up is adequate. If a regulatory authority requested documentation of how a specific report was prepared, who approved the most recent version of a key agreement, or what changes had been made to a PSMF before submission, could that information be produced without manually reconstructing it from emails and file histories?
For most pharma companies, the answer will be no. Without a smarter approach, companies will find themselves compromised. Most drug portfolios today are larger, and affiliate structures more complex than a decade ago, while the regulatory bar for documentation and traceability is considerably higher. All of these converging pressures make the case for a more systematic approach to PV workflow management that works with established safety databases rather than around them.
About the author

Gyöngyi Mezey is director of product management at Qinecsa Solutions, where she leads development of the company’s PV workflow automation platform, drawing on nearly two decades of hands-on pharmacovigilance experience, spanning drug safety operations, clinical coding and PV consulting at organisations including PAREXEL, Roche and IQVIA. She is based in London, UK.



























