In This Article
- Executive Summary
- What Intake Actually Decides
- Day Zero and Day Fifteen: The Clock Behind the Shortcuts
- Failure Point One: Duplicate Detection Across Intake Channels
- Failure Point Two: Incomplete Minimum Criteria for a Valid Case
- Failure Point Three: The Source Document and the Database Do Not Match
- Failure Point Four: Inconsistent MedDRA Coding of the Same Verbatim Term
- Failure Point Five: Unstructured and High Volume Channels
- Automation and AI at Intake: Genuine Help, New Governance
- What a Working Intake Quality System Looks Like
- Conclusion
- For Further Reading
- References & Sources
Executive Summary
Everything downstream in pharmacovigilance depends on what happens in the first hours after a case arrives. Signal detection, periodic reports, risk management plans, regulatory submissions, and inspection outcomes all rest on the accuracy of a set of decisions made at intake by people working under a clock they did not set. Intake is where most of the quality is won or lost, and it is the part of the safety operation that receives the least senior attention.
The pattern is consistent across companies of every size. Intake failures are rarely dramatic. They are small, repeatable judgments: a case invalidated because a patient identifier was not captured, a duplicate that entered through a second channel and was never merged, a verbatim term coded one way on Monday and another way on Thursday. Individually each one looks like a rounding error. Together they produce late expedited reports, rejected E2B(R3) transmissions, and signal detection that misses something real because the evidence was split across duplicate records or scattered across three preferred terms.
This article names five specific failure points at intake, ties each to the regulatory consequence it produces rather than leaving the risk abstract, and describes what to do about each. It also gives an honest read on automation and AI assisted intake, which genuinely helps with duplicate detection and triage and also introduces quality risk that now has to be governed under the frameworks regulators published in 2024 and 2025.
What Intake Actually Decides
Ask most safety leaders where the quality risk sits in their case processing operation and the answer will be medical review, causality assessment, or narrative writing. Those are the visible parts of the work, the parts staffed by physicians and senior scientists, and the parts that get discussed in governance meetings. Intake, by contrast, is often described as data entry. It is the step that gets outsourced first, staffed by the least experienced people, and measured almost entirely by throughput.
That framing is wrong, and it is expensive. Intake is not transcription. Intake is a sequence of regulatory determinations made in the first hours after information arrives, and each of those determinations constrains everything that can happen afterward.
Consider what actually gets decided at intake. Whether this contact is a valid case at all. Whether the four minimum criteria are present. Whether this is a new case or the same event already in the database under a different case number. What the reported event actually was, in the reporter’s own words, before anyone codes it. Whether the event is serious. What the awareness date is, which sets the reporting clock. Which product is the suspect product. Whether follow up is needed and what specifically to ask for.
Every one of those decisions is reversible in theory and very difficult to reverse in practice. A case invalidated at intake does not get a second look, because nothing triggers a second look. A duplicate that is not caught at intake becomes two independent case lifecycles, each generating its own follow up, its own submissions, and its own contribution to the statistics used for signal detection. A verbatim term captured loosely at intake constrains what the coder can do downstream, because the coder codes what is written, not what was said.
The asymmetry that makes intake different
Downstream steps in case processing have a useful property: they operate on data that is already in the system, so errors are at least discoverable. A medical reviewer can see a questionable causality assessment. A quality reviewer can compare the narrative to the coded fields. A periodic report author can notice that a case looks odd.
Intake errors do not have that property. The information that was lost at intake is not in the system to be found. When a case is invalidated, nothing remains to audit except the decision itself, and the decision looks reasonable on its face because the record shows a missing field. When a duplicate is created, both records look complete and internally consistent. The only way to find intake errors is to go back to the source document, which almost nobody does at scale.
This is why intake failures tend to surface through regulators rather than through internal quality systems. An inspector with the source documents in hand can see what the company could not.
Day Zero and Day Fifteen: The Clock Behind the Shortcuts
To understand why intake shortcuts happen, you have to understand the clock. Under 21 CFR 314.80(c)(1)(i), an applicant must report each adverse drug experience that is both serious and unexpected, whether foreign or domestic, no later than 15 calendar days from initial receipt of the information by the applicant.2 The EU framework works the same way. Good pharmacovigilance practice defines day zero as the date the information first reaches anyone in the organization or anyone acting on its behalf, which includes contract call centers, medical information vendors, sales representatives, and affiliates.4
That definition is the whole problem. Day zero starts when the information arrives at the edge of the organization, not when it arrives at the safety database. The clock is running during the hours or days it takes for a call center to route a contact, for an affiliate to translate a report, or for an email inbox to be triaged. And the clock does not pause for follow up. If a case arrives incomplete, the company still has fifteen days from the original awareness date, not fifteen days from the date the missing information finally arrives.
This produces a specific and predictable operational pressure. A case that is incomplete at intake consumes the reporting clock while follow up is chased. Every day spent trying to reach a reporter who does not answer the phone is a day gone from the fifteen. By day eight or nine, a case processor with an incomplete record faces a choice that nobody wants to write down: submit something thin, or keep working the case and risk being late.
Where the fifteen days actually go
| Stage | Typical elapsed time | What consumes it |
|---|---|---|
| Contact received at the channel edge | Day 0 | Call center, email, web form, affiliate, sales representative, literature vendor. The clock starts here regardless of whether the safety group knows. |
| Transfer into the safety system | Days 0 to 3 | Routing rules, safety data exchange agreements, batch transfers, translation, manual re-keying between systems. |
| Validity and duplicate determination | Days 1 to 4 | Minimum criteria check, database search, decision on whether this is a new case or a follow up to an existing one. |
| Data entry and coding | Days 2 to 6 | Verbatim capture, MedDRA coding, product coding, seriousness and expectedness determination, narrative drafting. |
| Follow up attempts | Days 3 to 12 | Outreach to reporter, waiting for response, second and third attempts, escalation. This is where the clock disappears. |
| Medical review | Days 8 to 12 | Physician assessment of causality, seriousness, and labeling. Queue depth here is a common source of lateness. |
| Quality check and submission | Days 12 to 15 | Final review, E2B(R3) generation, gateway transmission, acknowledgment handling and resubmission if rejected. |
Two things stand out in that sequence. The first is how much of the fifteen days is consumed before the case is fully formed. The second is that the last stage, gateway transmission, is not the end. A negative acknowledgment sends the case back, and the clock does not restart.
The medical review queue is a reporting compliance risk, not just a resourcing one. In its March 2026 warning letter to a marketing application holder, FDA cited a written procedure requiring most serious adverse reactions to enter medical review by calendar day 9 and complete it by calendar day 10. Cases sat in medical review status well beyond that window. One case received on December 9, 2024 entered medical review on December 16 and was not reviewed until February 3, 2025, after FDA identified it during the inspection. It was submitted on February 5.1 The procedure was correct. The queue was not managed against it.
Failure Point One: Duplicate Detection Across Intake Channels
The same adverse event frequently arrives more than once. A patient calls the medical information line. The same patient tells their physician, who reports through a different route. A study coordinator submits the event. A published case report describes it. A regulator forwards it back to the marketing authorization holder. Each of these arrivals looks like a new case to the person receiving it, because each arrives through a different channel with a different reporter and a different level of detail.
Duplicate detection is therefore not a database housekeeping task. It is an intake determination that has to be made before a case number is issued, and it has to be made against every channel, not just the one the case arrived through.
What duplicates do to signal detection
The regulatory consequence here is the one that matters most and gets discussed least. Statistical signal detection methods compare the observed number of reports for a drug and event pair against what would be expected. Duplicates inflate the observed count. That sounds like it would help find signals, and sometimes it does, but the more common outcomes are worse.
Duplicates create false signals that consume evaluation resources and dilute attention. They also mask real ones, because the same underlying event split across two records with different coded terms contributes to two separate low counts rather than one count that crosses a threshold. And they distort the case series a reviewer reads when a signal is being worked up, because the reviewer sees what looks like corroborating evidence from independent reporters when in fact it is one patient counted twice.
Regulators are explicit that this is a live problem in their own databases. FDA states plainly among the limitations of its public adverse event dashboard that there are many instances of duplicative reports and some reports do not contain all the necessary information.10 EMA maintains a dedicated addendum to its pharmacovigilance guidance covering duplicate management, including how organizations should detect, confirm, and manage duplicate cases and how to inform the agency of suspected duplicates in EudraVigilance.5
The published evidence gives a sense of scale. When the vigiMatch probabilistic matching method was applied to the World Health Organization global database for reports submitted between 2000 and 2010, 2.5 percent of the reports with sufficient information to be evaluated were classified as suspected duplicates. The rate was much higher for two categories that matter disproportionately: 11 percent for literature reports and 5 percent for reports with a fatal outcome.6 Those are exactly the reports that drive signal work.
What to do about it
- Search before you create. Make a documented database search a required, evidenced step before a new case number is issued, not an optional check afterward. The search should cover all channels and all case statuses, including invalidated and closed cases.
- Search on the fields that actually match. Patient age, sex, country of origin, event onset date, reported drugs, and reported reactions are the fields probabilistic methods rely on. Searching on reporter name alone finds almost nothing, because the reporter usually differs between channels.
- Treat literature and regulator forwarded cases as high risk. These are the two categories with the highest duplicate rates, and both routinely describe a case the company already holds.
- Instrument the merge. When a duplicate is confirmed, the merge decision, the surviving case, and the superseded case identifiers all need to be recorded. Regulators will ask how you know the merged record is complete.
- Measure the rate. If your operation reports a duplicate rate of zero, that is not a quality result. It means duplicates are not being detected.
Failure Point Two: Incomplete Minimum Criteria for a Valid Case
A valid individual case safety report requires four elements: an identifiable patient, an identifiable reporter, a suspect product, and an adverse event. This is the standard set out in ICH E2D and carried into both FDA and EU expectations.3 FDA’s draft guidance on postmarketing safety reporting applies the same four elements to information arriving through the internet and other digital channels.21
The rule sounds simple. In practice it produces two opposite failure modes, and both are serious.
Over-invalidation: throwing away reportable cases
The first failure mode is invalidating cases that were actually valid. The identifier was in the source document, but the intake agent did not extract it, or applied a narrower internal definition of an identifiable patient than the regulation supports.
This is not hypothetical. FDA’s March 2026 warning letter to a marketing application holder describes exactly this pattern. The company and its call center contractors invalidated 15-day alert reports for lack of patient identifiers. During the inspection, FDA reviewed the source documents and found valid patient identifiers in them. One case involved a consumer reporting a death for a male patient receiving semaglutide. The case was invalidated because the patient identifier was not captured. FDA found the identifier in the source documents. The reports were not submitted until FDA raised them during the inspection.1
The same letter describes a second over-invalidation pattern with a different root. The company’s written procedure excluded reports from the definition of adverse reaction where reporters specifically stated they believed the events to be unrelated or that a causal relationship could be excluded. FDA noted that this definition is inconsistent with its regulations, which define an adverse drug experience as any adverse event associated with the use of a drug in humans, whether or not considered drug-related. Serious and unexpected events were rejected at intake because the reporter had volunteered that they did not think the drug caused them. The company’s own root cause review found that while the exclusion was consistent with a foreign regulatory authority’s rules, it was not consistent with United States requirements.1
That is a useful lesson for any organization running a global safety operation on one set of procedures. A validity rule that is correct in one jurisdiction can be a reporting violation in another, and the intake agent applying it has no way to know.
Under-collection: accepting cases that are technically valid and practically useless
The second failure mode is the opposite. The four elements are present, so the case is opened and processed, but nothing else was collected. The result is a valid case that contributes almost nothing to safety understanding.
The vigiGrade completeness score was developed to measure exactly this. Applied to the World Health Organization global database, 13 percent of studied reports achieved a completeness score above 0.8, the threshold used to classify a report as well documented. Median completeness across the database was 0.41.7 Most reports in the world’s largest safety database are thin.
Thin cases are not a neutral outcome. They are the cases that cannot support causality assessment, cannot be used in a signal work-up, and generate the follow up burden that consumes the reporting clock on the next case.
The follow up trap. The same FDA warning letter describes a written procedure that did not require follow up on reported adverse events if consent was not obtained from the reporter and the reporter was a non-health care professional. FDA’s position is direct: the regulations do not require obtaining consent to acquire additional information. One case involved a non-health care professional reporting the death of a patient. It was closed without being reported because consent had not been obtained. Another involved a physician reporting a patient death by suicide, with no documented attempt to obtain additional information, including patient identifiers. As of the date of the letter, that case had not been submitted.1 A procedural rule invented for privacy reasons became a reporting failure.
What to do about it
- Write the validity rule against the regulation, not against convenience. Compare your definition of each of the four elements to ICH E2D and to each regional requirement you operate under. Where they differ, the procedure needs regional branches, not a single lowest common denominator.
- Make invalidation a reviewed decision. Any case invalidated for missing minimum criteria should be subject to a documented second review against the source document, at least on a sampling basis. Invalidation is a submission decision and should be treated as one.
- Separate validity from completeness. A case can be valid and still poor. Track both. Report both. A validity rate of 100 percent with a completeness score in the bottom quartile is a warning, not an achievement.
- Never make follow up conditional on anything the regulation does not require. Consent, reporter type, and perceived causality are not gates on the obligation to investigate.
Failure Point Three: The Source Document and the Database Do Not Match
The third failure point is the quietest. The case is valid, the duplicate check passed, the record is reasonably complete, and it still does not match what the reporter actually said.
Source document mismatch happens for ordinary reasons. A call center agent summarizes a fifteen minute conversation into a few fields. A verbatim term is paraphrased into clinical language before anyone codes it. A date is entered in the wrong format between a European affiliate and a United States database. A translation smooths away a detail that turned out to matter. Information present in an attached email or a scanned form is never transcribed because the intake screen has no field for it.
None of these is a dramatic error. All of them break the chain between the record and the source, and that chain is what an inspector follows.
Why this is a data integrity finding, not just a quality issue
The ALCOA+ expectations that govern data integrity in regulated operations apply to safety data as much as to manufacturing records. Data should be attributable, legible, contemporaneous, original, and accurate, along with the additional attributes of complete, consistent, enduring, and available. A safety record that does not match its source document fails accuracy and originality at once.
The practical consequence is that an inspector who pulls source documents can find intake errors that your internal quality system structurally cannot. That asymmetry is why source data verification of safety cases is becoming a standard remediation commitment. In its response to the FDA findings described above, the company committed to drafting work instructions related to ICSR quality checks and verification, including source data verification, and to a phased transition of safety case intake from contracted call center agents to insourced patient safety agents who are health care professionals.1
That second commitment is worth pausing on. It is an acknowledgment that the skill level of the person at the point of intake determines the quality of everything after it. Intake staffed as a low-skill transcription function produces low-skill transcription results, and no amount of downstream medical review recovers what was never captured.
Paraphrased verbatim
The reporter said one thing and the record says a cleaner clinical version of it. The coder then codes the paraphrase, so the coded term is two steps removed from what was reported.
Dropped detail
Concomitant medications, medical history, dechallenge and rechallenge information, or timing detail present in the source but never entered because no field prompted for it.
Date and format drift
Onset dates, awareness dates, and receipt dates transposed between regional formats or between systems. Awareness date errors move the reporting clock, which is a compliance problem on its own.
Unreconciled channel handoff
Information captured by a vendor, affiliate, or partner under a safety data exchange agreement that arrives in a different structure and is re-keyed without reconciliation back to the original record.
What to do about it
- Keep the source, and keep it linked. The recording, the email, the scanned form, or the vendor transfer file should be attached to the case and retrievable in one step. If the source has to be hunted for, verification will not happen.
- Run source data verification on a defined sample. Weight the sample toward fatal and serious cases, cases from new channels, cases from new vendors, and cases where the initial record was thin.
- Capture verbatim before anyone interprets it. The intake screen should have a field that holds the reporter’s own words, protected from later editing, separate from the clinical restatement.
- Reconcile every partner transfer. Safety data exchange agreements should specify reconciliation frequency, the fields to be reconciled, and who resolves discrepancies. Reconciliation that is agreed but not performed is a common inspection finding.
Failure Point Four: Inconsistent MedDRA Coding of the Same Verbatim Term
MedDRA coding is where intake quality becomes measurable, because coding drift is visible in the data even when the underlying cases look fine. The same verbatim term, coded by two people on two days, becomes two different preferred terms. Over months, a single clinical concept scatters across several terms and the pattern that would have been obvious becomes invisible.
The MedDRA Term Selection: Points to Consider document exists because this problem is well understood. It is an ICH-endorsed guide, updated annually in step with the March MedDRA release, that covers term selection for adverse events, product quality issues, medication errors, medical history, investigations, and off-label use, among other categories.11 Its purpose is to promote accurate and consistent term selection so that coded data can be shared and understood across companies and regulators.
Splitting and lumping
Two opposite errors do the damage. Lumping means coding dissimilar events under one broader umbrella term, which obscures a specific signal inside a general one. Splitting means coding similar events to several different terms, which lowers the count on each and keeps any of them from crossing a detection threshold.
Neither error is visible in a single case. Both are visible in aggregate, which is precisely why they need to be measured in aggregate rather than caught case by case.
The regulatory consequence runs in two directions. Downstream, coding drift degrades signal detection, because disproportionality methods depend on consistent term assignment to produce meaningful counts. Upstream, coding inconsistency shows up in periodic reports, risk management plans, and regulatory responses where the same event appears under different labels across documents, which is difficult to explain in an inspection.
The coding consistency check that most operations skip
Take the fifty most frequent verbatim terms received in the last quarter. For each, list every preferred term it was coded to and the count for each. Any verbatim term that maps to more than one preferred term is a candidate for a coding convention. Any preferred term that receives many dissimilar verbatim terms is a candidate for review as an umbrella that may be hiding something.
This takes a few hours to build and it is the single most informative view of intake coding quality most organizations do not have.
What to do about it
- Maintain a company coding convention document, aligned to the current MedDRA Term Selection: Points to Consider version, that resolves the terms your products actually generate. Update it with each MedDRA release, and record the rationale for each convention.
- Version your coding decisions. When a convention changes, record when it changed and whether historical cases were recoded. Unexplained shifts in term frequency at a version boundary are difficult to defend later.
- Run periodic coding consistency reviews across coders and across vendors. Inter-coder agreement on a blinded set of verbatim terms is a real metric and a fair one.
- Route ambiguous terms to a named decision maker rather than letting each coder resolve them independently. Ambiguity resolved locally is the mechanism by which drift enters.
Failure Point Five: Unstructured and High Volume Channels
The fifth failure point is the one growing fastest. Traditional intake assumed a bounded set of channels: a phone line, a fax, a form, a partner transfer. That assumption no longer holds. Cases now arrive through scientific literature, call center audio, patient support programs, market research, social and digital media, product complaint systems, and increasingly through channels the safety group does not own.
What these channels share is that the information is unstructured, the volume is high, and the reporting obligation still applies from the moment the information reaches anyone acting on the company’s behalf.
Literature
Literature is the highest duplicate risk channel in the published evidence, at 11 percent suspected duplicates in the vigiMatch work.6 It is also the channel with the most complicated scope rules. EMA operates a medical literature monitoring service covering a defined set of active substance groups, and marketing authorization holders are not required to report to EudraVigilance the suspected adverse reactions recorded in the listed medical literature for products the agency monitors. They must continue to monitor all other medical literature and report what they find.14
That split creates a scope management burden that is easy to get wrong in both directions: reporting cases the agency already captured, or failing to monitor substances that fall outside the service. Neither error is visible without a deliberate reconciliation between the agency’s covered list and the company’s product portfolio.
Call center audio
Call centers are where day zero most often starts and where intake quality is most often outsourced. The FDA warning letter discussed earlier is instructive here as well: the company identified problems with one call center contractor, terminated that contract, switched to a second contractor, and opened a deviation. Despite the change of vendor and the completion of corrective actions, cases continued to be invalidated for lack of a patient identifier when identifiers were available.1 Changing the vendor did not fix the intake rule, the training, or the oversight.
The general point holds beyond that case. Under both FDA and EU frameworks, delegating intake does not delegate the obligation. The application holder remains responsible for compliance including when it contracts with a vendor to fulfill any of its adverse event responsibilities.
Digital sources
Digital and social channels generate enormous volume with a very low proportion of valid cases, which is a difficult combination. The published work on this is worth reading carefully because it quantifies both sides. In a study of machine learning applied to identifying individual case safety reports in social and digital media, a rule-based approach reached 65 percent accuracy, machine learning annotation improved that to 74 percent, and an additional detector reached 83 percent accuracy on a blind test set of 2,500 posts. The final model completed in 48 hours a task estimated to require roughly 44,000 hours of human expert effort.12
Two conclusions follow. The first is that manual review of digital channels at scale is not realistic. The second is that 83 percent accuracy is a real number with real error in it, which is why the governance question in the next section is not optional.
The under-reporting context that makes all of this matter. A systematic review of under-reporting to spontaneous reporting systems found that under-reporting is significant and widespread, including for serious and severe reactions.13 The cases that reach intake are already a small fraction of the events that occurred. Losing a further share of them at intake, through invalidation, duplication, or coding drift, compounds a problem that starts well before the company is involved.
Automation and AI at Intake: Genuine Help, New Governance
Automation at intake is not a future question. It is already deployed, and for good reasons. The three tasks it handles well map directly onto three of the five failure points described above.
Probabilistic duplicate detection works. vigiMatch has been in routine use on the World Health Organization global database and represents a statistical approach deployed at scale.6 Automated triage of high volume, low yield channels works, within a stated accuracy range.12 Structured extraction from unstructured sources, including transcribed call audio and literature abstracts, reduces the transcription burden that produces source mismatch.
What has changed is that these capabilities now sit inside an explicit regulatory framework rather than in a gap. Three documents define the current expectation.
EMA reflection paper on AI in the medicinal product lifecycle (September 2024)
Sets out a risk-based and human-centered approach across the lifecycle. It notes that pharmacovigilance applications may allow more flexible modeling, including incremental learning for classification and severity scoring of adverse event reports, while making clear that it remains the marketing authorization holder’s responsibility to validate, monitor, and document model performance and to include AI operations within the pharmacovigilance system.15
FDA draft guidance on AI to support regulatory decision-making (January 2025)
Proposes a risk-based credibility assessment framework with a seven-step process for establishing and documenting the credibility of an AI model for a specific context of use, covering nonclinical, clinical, post-marketing, and manufacturing phases.16 The context of use concept is the important one for intake: a model used to flag possible duplicates for human confirmation carries different risk from a model that invalidates cases without review.
CIOMS Working Group XIV report on AI in pharmacovigilance
Provides an internationally aligned set of guiding principles for AI use in drug safety, including a risk-based approach, human oversight scaled to risk, transparency, data privacy, fairness, and governance.17 It is written as durable principles rather than technical instructions, which makes it usable as the backbone of an internal policy.
The honest trade-off
Automated intake removes one category of error and introduces another. Human intake produces errors that are individual, varied, and random. Automated intake produces errors that are systematic, consistent, and repeated across every case the model touches until someone notices.
That difference matters more than the headline accuracy number. A human agent who misapplies a validity rule affects the cases they personally handle. A model that misapplies a validity rule affects every case in the channel, silently, at volume. The upside is that systematic errors are far easier to detect and correct once you are looking for them, which is exactly what monitoring is for.
The governance questions that follow are practical rather than philosophical:
- What is the context of use, stated narrowly? Flagging duplicates for human confirmation is a different context from auto-merging. Extracting a suspect product for review is different from setting the seriousness field. Write the narrow version.
- What is the human oversight point, and does the reviewer have what they need? A reviewer confirming a model’s duplicate flag needs to see both records and the matching basis. A reviewer approving an extracted field needs the source. Oversight that is nominal is not oversight.
- How is performance monitored after go-live? Intake data distribution shifts constantly as products launch, labels change, and channels grow. A model validated on last year’s mix is not validated on this year’s.
- What happens to the cases the model declined? A false negative at intake is invisible by construction. Sampling declined items is the only way to see it, and it needs to be a standing activity rather than a validation exercise.
- Is the AI operation inside the pharmacovigilance system master file and the quality system? EMA’s position is that AI operations belong within the pharmacovigilance system, not alongside it.15
What a Working Intake Quality System Looks Like
The five failure points share a structural feature: none of them is caught by the controls most safety operations already run. Case processing metrics measure timeliness and volume. Quality review measures whether the record is internally consistent. Neither of those touches whether the record matches the source, whether the case should have been created at all, or whether the coded term is the same one used for the same verbatim last month.
An intake quality system that works has four parts.
1. Metrics that look at intake, not just at output
| Failure point | Leading metric | What a bad result looks like |
|---|---|---|
| Duplicates | Suspected duplicate rate by channel, and confirmed duplicate rate among those suspected | A rate near zero, or a rate that differs sharply between channels without explanation |
| Minimum criteria | Invalidation rate by channel and by reason, with source review of a sample of invalidations | Rising invalidation from one vendor or one channel; invalidation reasons that do not map to the four elements |
| Source mismatch | Source data verification discrepancy rate, weighted to serious and fatal cases | Discrepancies concentrated in specific fields, most often onset date, concomitant medications, or seriousness |
| Coding drift | Number of distinct preferred terms per high-frequency verbatim term, tracked over time | The count rising after a staffing change, a vendor change, or a MedDRA version update |
| Unstructured channels | Time from channel receipt to safety system entry, by channel | Any channel where the median exceeds two or three days, because that is clock consumed before work begins |
2. Ownership that includes the channel edge
Day zero starts at the channel, so the quality system has to extend to the channel. In practice this means the safety group owns the intake rules applied by every vendor, affiliate, and partner, owns the training those agents receive, and reviews their output rather than relying on the vendor’s own quality reporting. Safety data exchange agreements should name the reconciliation activity, its frequency, and who resolves discrepancies.
3. Procedures written against the regulation for each region
A single global intake procedure is efficient until it encodes a regional rule as a global one. The validity definition, the follow up obligation, and the treatment of reporter causality statements all differ enough between regions to produce reporting violations when flattened. Where a global procedure is used, the regional branches need to be explicit and the intake agent needs to know which branch applies before making the determination.
4. A verification loop that goes back to the source
This is the part that is usually missing. Every other control operates on data already in the system. Source data verification is the only control that can find what intake lost. It does not need to be applied to every case. It needs to be applied to a defined, risk-weighted sample, on a schedule, with findings routed into corrective action rather than into a quality report nobody acts on.
A reasonable first ninety days. Build the verbatim-to-preferred-term view for the last quarter and see how much drift is already present. Pull a sample of invalidated cases from each channel and review them against source documents. Map every channel where a contact can arrive and record who owns each one and how long it takes to reach the safety database. Reconcile your product portfolio against the EMA medical literature monitoring covered substance list. None of this requires new systems, and all of it will tell you something you do not currently know.
Conclusion
Pharmacovigilance quality is usually discussed at the level of signal detection methods, risk management plans, and periodic reports. Those are the visible outputs, and they get the governance attention. But every one of them is a function of the case records underneath, and those records are made in the first hours after a contact arrives, by people working against a fifteen day clock that started before the safety group knew the case existed.
The five failure points described here are specific and each has a specific regulatory consequence. Duplicates distort the counts that signal detection depends on. Incomplete minimum criteria produce late expedited reports or, worse, cases that are never submitted at all. Source mismatch is a data integrity finding waiting for an inspector with the source documents in hand. Coding drift buries real patterns across scattered terms. Unstructured and high volume channels arrive faster than manual intake can absorb them. Automation helps with several of these and creates a governance obligation of its own, which the EMA reflection paper, the FDA draft guidance, and the CIOMS Working Group XIV report have now made explicit.
None of this is solved by working harder at intake. It is solved by treating intake as a regulatory determination point with its own metrics, its own ownership that extends to the channel edge, its own regional procedures, and a verification loop that goes back to the source document. That is a modest amount of structure for the part of the operation that determines everything after it.
Sakara Digital works with pharma and biotech organizations building the data quality foundations that safety, quality, and regulatory functions depend on, including the governance structures now expected around AI assisted case processing. If you are looking at your own intake operation and want an independent perspective on where the real risk sits and what to fix first, we are happy to have that conversation.
For Further Reading
For Further Reading
- Pharmacovigilance Signal Detection with AI: What Regulators Expect
- AI-Powered Literature Surveillance in Pharmacovigilance
- Data Integrity and ALCOA+ in the Digital Age: Modernizing Compliance for Cloud and AI Systems
- Data Quality Metrics That Matter: How Pharma Leaders Measure Integrity and Readiness for AI
- Human-in-the-Loop Requirements for Pharma AI: What FDA and EMA Actually Expect
References & Sources
- U.S. Food and Drug Administration. “Warning Letter: Novo Nordisk Inc., MARCS-CMS 717576.” Center for Drug Evaluation and Research, March 5, 2026. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/novo-nordisk-inc-717576-03052026
- Electronic Code of Federal Regulations. “21 CFR 314.80: Postmarketing reporting of adverse drug experiences.” https://www.ecfr.gov/current/title-21/chapter-I/subchapter-D/part-314/subpart-B/section-314.80
- International Council for Harmonisation. “ICH Harmonised Tripartite Guideline E2D: Post-Approval Safety Data Management: Definitions and Standards for Expedited Reporting.” November 2003. https://database.ich.org/sites/default/files/E2D_Guideline.pdf
- European Medicines Agency. “Guideline on good pharmacovigilance practices (GVP) Module VI: Collection, management and submission of reports of suspected adverse reactions to medicinal products (Rev. 2).” https://www.ema.europa.eu/en/documents/regulatory-procedural-guideline/guideline-good-pharmacovigilance-practices-gvp-module-vi-collection-management-and-submission-reports-suspected-adverse-reactions-medicinal-products-rev-2_en.pdf
- European Medicines Agency. “Guideline on good pharmacovigilance practices (GVP) Module VI Addendum I: Duplicate management of suspected adverse reaction reports.” https://www.ema.europa.eu/en/documents/regulatory-procedural-guideline/guideline-good-pharmacovigilance-practices-gvp-module-vi-addendum-i-duplicate-management-suspected-adverse-reaction-reports_en.pdf
- Tregunno PM, Fink DB, Fernandez-Fernandez C, Lazaro-Bengoa E, Noren GN. “Performance of probabilistic method to detect duplicate individual case safety reports.” Drug Safety, 2014. PubMed 24627310. https://pubmed.ncbi.nlm.nih.gov/24627310/
- Bergvall T, Noren GN, Lindquist M. “vigiGrade: A Tool to Identify Well-Documented Individual Case Reports and Highlight Systematic Data Quality Issues.” Drug Safety, 2014. PubMed 24343765. https://pubmed.ncbi.nlm.nih.gov/24343765/
- U.S. Food and Drug Administration. “FDA Regional Implementation Guide for E2B(R3) Electronic Transmission of Individual Case Safety Reports for Drug and Biologic Products.” https://www.fda.gov/media/180748/download
- U.S. Food and Drug Administration. “FDA Adverse Event Monitoring System (AEMS) E2B(R3) Standards.” https://www.fda.gov/drugs/fda-adverse-event-monitoring-system-aems/fda-adverse-event-monitoring-system-aems-e2br3-standards
- U.S. Food and Drug Administration. “FDA Adverse Event Monitoring System (AEMS) Public Dashboard.” https://www.fda.gov/drugs/fda-adverse-event-monitoring-system-aems/fda-adverse-event-monitoring-system-aems-public-dashboard
- MedDRA Maintenance and Support Services Organization. “MedDRA Term Selection: Points to Consider, ICH-Endorsed Guide for MedDRA Users.” Release 4.24, March 2024. https://admin.meddra.org/sites/default/files/guidance/file/001006_termselptc_r4_24_mar2024.pdf
- Comfort S, Perera S, Hudson Z, et al. “Sorting Through the Safety Data Haystack: Using Machine Learning to Identify Individual Case Safety Reports in Social-Digital Media.” Drug Safety, 2018. https://link.springer.com/article/10.1007/s40264-018-0641-7
- Hazell L, Shakir SAW. “Under-reporting of adverse drug reactions: a systematic review.” Drug Safety, 2006;29(5):385-396. PubMed 16689555. https://pubmed.ncbi.nlm.nih.gov/16689555/
- European Medicines Agency. “Detailed guide regarding the monitoring of medical literature and the entry of relevant information into the EudraVigilance database.” https://www.ema.europa.eu/en/documents/other/detailed-guide-regarding-monitoring-medical-literature-and-entry-relevant-information-eudravigilance-database-european-medicines-agency_en.pdf
- European Medicines Agency. “Reflection paper on the use of Artificial Intelligence (AI) in the medicinal product lifecycle.” September 2024. https://www.ema.europa.eu/en/documents/scientific-guideline/reflection-paper-use-artificial-intelligence-ai-medicinal-product-lifecycle_en.pdf
- Federal Register. “Considerations for the Use of Artificial Intelligence To Support Regulatory Decision-Making for Drug and Biological Products; Draft Guidance for Industry.” January 7, 2025. https://www.federalregister.gov/documents/2025/01/07/2024-31542/considerations-for-the-use-of-artificial-intelligence-to-support-regulatory-decision-making-for-drug
- Council for International Organizations of Medical Sciences. “Working Group XIV: Artificial Intelligence in Pharmacovigilance.” https://cioms.ch/working_groups/working-group-xiv-artificial-intelligence-in-pharmacovigilance/
- Medicines and Healthcare products Regulatory Agency. “MHRA GPvP Inspection Metrics: April 2019 to March 2020.” https://assets.publishing.service.gov.uk/media/603cbbee8fa8f50495bda34d/MHRA_GPvP_Inspection_metrics_2019-20.pdf
- European Medicines Agency. “2024 Annual Report on EudraVigilance for the European Parliament, the Council and the Commission.” https://www.ema.europa.eu/en/documents/report/2024-annual-report-eudravigilance-european-parliament-council-commission_en.pdf
- Regulatory Affairs Professionals Society. “Novo Nordisk gets FDA warning letter for adverse event reporting violations.” https://www.raps.org/resource/novo-nordisk-gets-fda-warning-letter-for-adverse-e.html
- U.S. Food and Drug Administration. “Guidance for Industry: Postmarketing Safety Reporting for Human Drug and Biological Products Including Vaccines (Draft).” https://www.fda.gov/media/72504/download








Your perspective matters—join the conversation.